Your evaluation is your business.
Picari is where security teams run vendor bake-offs in private. Here's exactly how we protect that privacy, and what we don't claim.
You brief in private
Browse the directory, run a Briefing, and build shortlists for free, in private. No vendor can see you're looking.
You control disclosure
Vendors can't see or contact you until you initiate. When you do, they get your name, company, and requirements, nothing else.
You're never the product
We don't sell browsing data or user lists, and your Picari activity is never used to target you. Revenue comes from introductions both sides opted into.
The detail
How we back that up
Straight answers
What we claim, and what we don't
We'd rather be upfront about where we are today than make claims we can't back up.
Private by default. Briefing and shortlisting happen without vendors knowing.
Database-level isolation. RLS on every sensitive table.
EU data residency. Stored in Ireland (eu-west-1), TLS in transit, encrypted at rest.
GDPR-compliant. Fully aligned with EU/UK GDPR and Irish data-protection law.
No selling data. No browsing data or user lists sold, ever.
Vendor deal privacy. A vendor's deal activity is visible only to them, never public, never shared with other vendors.
SOC 2 or ISO 27001, not yet. It's on the near-term roadmap and actively in progress. Until then, we share current controls and progress with serious buyers under NDA.
End-to-end encryption. Data is encrypted in transit and at rest at the infrastructure layer, the standard model for platforms like ours.
Control after introduction. Once you choose to engage, the vendor receives your details, which is why nothing is shared until you initiate.
Finished. We're early-stage, our practices are evolving, and we welcome scrutiny, so ask us anything below.
Ask us anything about security.
Data handling, infrastructure, our practices. No questionnaire too detailed.
Security reports: info@picari.ai · also published in our security.txt.
This page describes controls visible to users today. It isn't a certification, audit report, or legal agreement. For those, see our Privacy Policy and Terms of Service.