Skip to main content

Prizm Security Architecture

The Prizm platform implements a comprehensive security model designed to provide both robust protection and flexible access management. Our security architecture addresses the complex requirements of modern enterprises while maintaining usability. It is designed for organizations that require enterprise-grade security without sacrificing the agility needed in today’s data-driven environments.

Security Design Principles

Defense in Depth

Multiple security layers protect critical assets. No single point of failure can compromise overall system security.

Least Privilege

Users receive the minimum access needed for their role. Access is granted on a need-to-know basis and reviewed regularly.

Separation of Duties

Critical operations require multiple approvers. No single user can complete sensitive actions unilaterally.

Zero Trust Architecture

Continuous verification regardless of network location. Trust is never assumed — all access requests are authenticated and authorized.

Privacy by Design

Data protection controls are built into the core architecture. Privacy is not an afterthought but a foundational design consideration.

Architecture Components

Authentication

The Prizm platform implements robust authentication mechanisms to verify user identities and secure access to resources. The system supports multi-factor authentication (MFA) to add an additional layer of security beyond passwords.
  • Multi-factor authentication (MFA) support
  • Single Sign-On (SSO) via SAML 2.0, OAuth 2.0, and OpenID Connect
  • LDAP directory integration for enterprise environments
  • Session management with configurable timeout policies

Authorization

Prizm utilizes a fine-grained authorization model that controls what authenticated users can access and perform. Resources are protected through policy-based access controls that enforce the principle of least privilege. The authorization process follows a structured workflow:
1

Identify the user

Identify the requesting user and their group memberships.
2

Collect role assignments

Collect all applicable role assignments — direct and via group membership.
3

Determine effective permissions

Determine effective permissions based on role precedence rules.
4

Apply constraints

Apply any tag-based or attribute-based constraints to the resolved permissions.
5

Enforce access decision

Make the final access decision and enforce it at runtime.

Data Protection

Prizm employs comprehensive data protection measures across the entire data lifecycle:

SSO Integration

Prizm offers comprehensive Single Sign-On (SSO) support, integrating with major identity providers including:
  • SAML 2.0 providers — Okta, Azure AD, OneLogin
  • OAuth 2.0 / OpenID Connect frameworks
  • LDAP directory services

Security Layers

Compliance Frameworks

The platform is designed to help organizations meet regulatory requirements. Our compliance-ready architecture includes built-in controls, audit capabilities, and reporting tools that streamline certification processes.

GDPR

General Data Protection Regulation

CCPA / CPRA

California Privacy Rights Act

HIPAA

Health Insurance Portability and Accountability Act

SOC 2 Type II

Service Organization Control 2

ISO 27001

Information Security Management System

Role-Based Access Control

Detailed RBAC model, roles, and permission matrix.

SSO Integration

Identity provider configuration and federation setup.

Data Protection

Encryption standards, classification, and masking policies.

Compliance

Regulatory framework coverage and audit capabilities.