Skip to main content

Overview

The Prizm platform is designed to help organizations meet regulatory requirements across multiple compliance frameworks. Compliance in Prizm is built into the core platform architecture through Privacy by Design principles, ensuring controls are always active and verifiable.

Supported Frameworks

GDPR

General Data Protection Regulation
EU personal data processing; any organization handling EU resident data.

CCPA / CPRA

California Privacy Rights Act
California resident data; US businesses above the revenue/data threshold.

HIPAA

Health Insurance Portability and Accountability Act
US healthcare data (PHI); covered entities and business associates.

SOC 2 Type II

Service Organization Control 2
SaaS and service providers; customer trust and assurance reporting.

ISO 27001

Information Security Management System
Global standard for systematic information security management.

GDPR

Platform Controls

Key Articles Addressed


HIPAA

For organizations handling Protected Health Information (PHI), Prizm provides controls that support HIPAA Security Rule requirements across all three safeguard categories:
  • Role-based access controls with documented assignment history
  • Workforce training record support
  • Contingency planning documentation
  • Access review and de-provisioning audit trail
Physical security of underlying cloud infrastructure is documented in Prizm’s Data Center Security policy and covered under the shared responsibility model with cloud providers.
  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Unique user identification via SSO and MFA
  • Automatic session logoff with configurable idle timeout
  • Comprehensive audit controls with immutable logs
  • End-to-end encryption for all PHI in transit
Prizm supports Business Associate Agreement (BAA) execution for covered entities. Contact your account team to initiate the BAA process.

SOC 2 Type II

Trust Services Criteria Coverage


ISO 27001

Annex A Controls Alignment

Prizm’s security architecture aligns with ISO 27001:2022 Annex A controls across the following domains:

Audit Capabilities

What Is Logged

Every significant action in Prizm generates an audit event:
  • User authentication events (login, logout, failed attempts, MFA)
  • Resource access events (view, create, edit, delete) with full context
  • Permission and role assignment changes
  • Administrative actions (configuration changes, user management)
  • Data export and download events
  • API access with client identification

Audit Log Attributes

Compliance Reporting

Prizm provides built-in reports to support certification workflows: Reports can be scheduled, exported as PDF/CSV/JSON, and integrated with GRC platforms via API.

Shared Responsibility

Compliance is a shared responsibility between Prizm and customer organizations: