Legal documents
Preferium AS · 999 323 286
info@preferium.com
Legal · Trust Centre
Trust and Security
Which controls are actually in place, which are not yet, and where you can verify it yourself. “Trust us” is not a security control.
For a concluded agreement, the document versions recorded in the accepted Order or signature apply. A new version on this website does not change the agreement by itself.
Jump to a section
Preferium AS · contact and company details
- Company
- Preferium AS
- Org. no.
- 999 323 286
- Registers
- Central Coordinating Register for Legal Entities (Enhetsregisteret, since 5 January 2013), Register of Business Enterprises (Foretaksregisteret) and VAT Register (Merverdiavgiftsregisteret)
- Office address
- Produksjonsveien 18, 2nd floor, 1618 Fredrikstad
- Postal address
- Sponheimveien 19, 1613 Fredrikstad
- Contact
- info@preferium.com · +47 977 91 286
1. How to read this page
This page describes the controls and known limitations of Preferium AI Edge, the product agencies resell, and of the preferium.com platform. It is not a certification, not an SLA and not a warranty; it creates no contractual commitment, and the Service Terms and the Data Processing Agreement alone govern Preferium's obligations and liability. A control is called implemented only when it exists in the deployed code or in a provider contract; plans are kept separate from implementation, and a control described here for preferium.com is not evidence that another system has the same control.
We distinguish between implementation in the software, confirmed operation and measures that are not yet available. Agreed security obligations apply to the specific delivery; a public description of a control is not by itself evidence that the obligation has been fulfilled.
2. Preferium AI Edge
The lists below state, control by control, what is in place in Preferium AI Edge and what is not yet. They follow the product's source code, its control registry (evidence observed on 11 September 2026) and its records of processing. Where a control is implemented but its production configuration has not been read back, we say so. These descriptions are information: the agreed security requirements are those in Section 5 of the Data Processing Agreement, and a product control becomes a contractual commitment only if a signed Order says so. The configuration of a specific client site, such as its control level, decides which controls apply to it.
In place
- Tenant isolation at database level. Each client workspace's data is tied to its owner and walled off by row-level security in the database, not only filtered in the application.
- Staff and support access. Support enters a client workspace only through a read-only view-as mode that shows a visible banner inside the workspace. Under Section 2 of the Data Processing Agreement, support access takes place only under a documented support case, is time-limited where practicable and is logged.
- Encrypted third-party tokens. Connected Google credentials (Search Console and Analytics) are encrypted with AES-GCM before they are stored and are never stored in readable form. TLS with HSTS is set on every response; encryption at rest is provided by the database provider under its contract and is not measured by us.
- Tamper-evident audit log. Sensitive actions are appended to a hash-chained audit log whose chain integrity is checked by the database. No external party has verified a production chain.
- Fail-safe serving. Any unexpected problem in the pipeline serves the original, untouched page. If Preferium's own data cannot be reached, the original page is served. Only successful HTML responses are rewritten; errors, redirects and non-HTML responses pass through. Logged-in and form traffic, such as a checkout, a login or the CMS admin, passes straight through. If the client's origin times out or errors, the last good anonymous copy keeps being served. If serving starts failing, the engine disables itself, and the kill switch serves the original site everywhere within about a minute. None of this covers an outage of Cloudflare itself or a DNS change at the client's DNS provider.
- Checks after deploy. After every deploy a real browser re-opens the live page and re-checks its core elements (title, meta description, H1 and structured data); a change that made things worse is rolled back automatically and the agency is told. Drift detection every 30 minutes repairs changes that something else overwrote. Every other change stays reversible with one click.
- Status page. status.preferium.com runs as a separate worker in its own failure domain, shows the live health of the platform and says so when it cannot read it. It stores no history, publishes no feed and sends no notifications.
- Incident process. Possible personal data breaches follow Section 9 of this page and Section 9 of the Data Processing Agreement: the Customer is notified without undue delay, with a first preliminary notice targeted within 24 hours where possible.
Not yet
- External penetration test. No external penetration test has been performed. The first engagement is in vendor selection; a summary will be published only when a test has actually taken place.
- Verified backup coverage and a rehearsed provider restore. Recorded runs exist from an earlier backup process, but those records do not establish that the stored copies can be recovered today. Current provider-managed backup and point-in-time recovery settings remain unverified. The replacement capture and restore path has not been verified end to end in production. The restore rehearsal used disposable local databases (11 September 2026), never a provider restore; no recovery time or complete recovery from loss of the database provider and authentication is claimed.
- Multi-factor authentication for privileged staff roles. The gate is implemented and tested, but its production configuration has not been read back, so we do not claim that it is in force.
- Enterprise single sign-on. SAML login is implemented, but no customer identity provider has been connected end to end.
- Verified scheduled deletion of closed workspaces. The deletion job was enabled on 19 September 2026. A scheduled run after activation and actual deletion outcomes still need verification, so a fixed deletion deadline is not confirmed (Section 11 of the Data Processing Agreement).
- Published software bill of materials. The workflow exists, but nothing has been generated, signed or published.
3. Controls of the preferium.com platform
The website and its compliance platform run as a Cloudflare Worker with a Cloudflare D1 database created in the EU jurisdiction. The following controls are implemented in the software:
- Owner-only administration behind Cloudflare Access. The administration routes sit behind a Cloudflare Access application that admits only the owner's verified email through an MFA-capable login. Access is the outer gate, not the only gate: the Worker independently verifies the Access JWT on every administration request against the team's public signing keys, checks the audience and the email allowlist, and issues its own short-lived session with CSRF protection.
- Tamper-evident evidence chain. Every consent decision, privacy case action, legal publication and administrative action is recorded as an evidence event that carries the SHA-256 hash of the previous event. Administrator actions require a stated purpose and reason and are written to an immutable audit table.
- Encrypted case details. Privacy and incident case content is encrypted with AES-GCM under a versioned keyring; lookup indexes are keyed digests. Case lists show metadata only, and sensitive case content is decrypted only after the access has been recorded with a reason.
- Versioned legal registry. The nine legal documents are published as exact source snapshots with SHA-256 hashes, effective times and a provenance record tied to the source commit and build manifest. The version, effective time and hash are shown above every document.
- Consent that fails closed. No optional technology loads unless a purpose has a verified configuration, a published consent policy and your affirmative choice. Global Privacy Control is honored as a standing opt-out. Consent receipts are pseudonymous and contain no raw IP address.
- Verified privacy intake. The privacy request form is protected by Cloudflare Turnstile and rate limiting, verifies the reply address through a one-time token, records the original time of receipt and derives the statutory deadline from the visitor's regime (GDPR one calendar month, CCPA/CPRA 45 days).
- Retention with evidence. Retention policy version 1 fixes the periods per data class (privacy choice 180 days; consent evidence, administrator audit and privacy requests three years; incidents five years). A scheduled nightly job deletes what has expired, respects legal holds and records one evidence entry per class.
- Backup. The database backup is the provider's built-in point-in-time history of 30 days (Cloudflare D1 Time Travel). We keep no separate recovery copies. A restore is documented for the point in time actually restored and must not make earlier deletions available again without handling the deletion and any valid retention requirement.
- Form protection and no third-party assets. Contact, waitlist and privacy forms use Cloudflare Turnstile and rate limiting. Fonts and design assets are self-hosted; Turnstile is the only third-party script that loads without your consent, and the Google Analytics tag loads only after you choose analytics in the consent manager.
Digital case handling is unavailable when the necessary authorization, configuration or audit trail cannot be confirmed. You can still contact info@preferium.com.
4. Limitations and open maturity items
Preferium is not ISO 27001 certified and has no SOC 2 report as of this version. We do not claim that an external penetration test is carried out annually, and we do not claim three independent backup systems without verified evidence. Such requirements apply only if they are stated in a specific Order and can actually be met.
These documents have not been reviewed by external legal counsel. Preferium has not appointed Robert André Johansen as Data Protection Officer; he is the privacy contact. A formal DPO is stated only once an independent and qualified function has actually been established.
Production readiness of each control is confirmed at release: the database, keys, Access configuration and the exact deployed legal manifest must all be in place before the platform serves administration, privacy or consent routes.
5. Data, providers and geography
The Customer's data remains the Customer's. Client workspace data is stored in the EU (Stockholm). Edge delivery runs on Cloudflare's global network, and AI measurement providers are listed in the subprocessor register. AI calls, citation measurement, email, payment, support and monitoring may therefore involve processing outside the EEA. The Subprocessor Register separates service scope, documented public terms and matters not confirmed for the actual account.
Loss of ordinary application access, deletion from active systems, expiry of recovery copies and physical removal at the provider are different events. A deletion confirmation must explain which copies may remain, the restriction on their use and their deadlines.
6. Export and switching
The Customer may request export and switching under the Service Terms. Exportable categories include account and user data, domains, the Customer's configuration, published changes, reports and measurement data to the extent they are tied to the Customer's use and exist in the Service.
Export is delivered in common structured formats such as JSON, CSV or equivalent where suitable. It does not include secrets, abuse signals, vulnerability information, source code, model weights, internal prompt and rule sets, general algorithms or derivations that are Preferium's trade secrets, unless such a part is necessary to use the Customer's exported data.
Available export formats, interfaces and known limitations must be documented for the specific system. Agreed switching rights follow the Service Terms; this page does not confirm general Data Act compliance. Preferium charges no separate switching fee, but outstanding subscriptions and separately ordered work remain due.
7. Termination and Frozen Delivery
Ordinary cancellation stops renewal. Frozen edge delivery is a separate continued state for qualifying contracts, not a general right on every account closure. It has no active optimization and can be ended by technical disconnection. Personal data that is not needed for the limited serving is not retained merely because the published configuration is frozen. There is no buyout of deployed changes and no fee for keeping them frozen.
Preferium does not show a public 503 notice telling visitors that a customer has cancelled. The Customer and Preferium cooperate on a neutral DNS and origin transition.
8. Vulnerability disclosure
Report a security vulnerability to info@preferium.com. If the report contains exploit details, customer data or session tokens, write first without them and we arrange an encrypted channel. Reports in English or Norwegian are accepted. The machine-readable contact is published at /.well-known/security.txt.
In scope: preferium.com and the subdomains Preferium operates, preferium.no, and Preferium's own code path on client hostnames served through Preferium AI Edge. Out of scope: content and hostnames the client controls (report those to the site owner), third-party services such as Cloudflare, Supabase or Stripe (report those to the provider), denial of service, social engineering, physical access, and best-practice recommendations without a demonstrable issue.
Do not retrieve more data than necessary to show the issue, stop at the smallest proof, do not disrupt other customers and do not disclose details before we have had a reasonable opportunity to fix the issue. Responsible reporting in good faith is treated fairly. We do not currently offer monetary rewards.
Response targets: acknowledgement within 72 hours; initial triage and severity within 7 days; a status update or a fix within 30 days; coordinated disclosure 90 days after acknowledgement or when the fix ships, whichever is earlier. These are targets, not contractual deadlines. If we expect to miss one, we tell you before it passes. Details that could increase risk may be withheld until remediation is complete.
9. Incidents and personal data breaches
For possible personal data breaches, detection, awareness of the breach, confirmed facts and measures taken are kept separate. A deadline notice does not decide whether notification is legally required. The controller assesses notification to the supervisory authority without undue delay and where feasible within 72 hours of becoming aware, subject to the statutory risk exception; information to affected persons follows a separate assessment of high risk. The processor's notice to the customer is given without undue delay. Notification decisions and actual dispatches are documented separately; acceptance by an email provider does not prove delivery or reading.
Preferium AS · organization no. 999 323 286 · Sponheimveien 19, 1613 Fredrikstad, Norway · +47 977 91 286