Skip to main content

The Console side: what Prometheus Research Labs holds and where

The AlphaAgent Console is the one part of AlphaAgent that Prometheus Research Labs operates. This page is the outside-in view: which classes of data about you it holds, where it runs, how you sign in to it, how long records are kept, which third parties are involved, who at Prometheus Research Labs can see what, and how you request deletion.

Who this is for​

CTOs, CISOs and data-protection officers completing a vendor assessment.

Before you start​

The Console has two hostnames. api.alphaagent.prometheusrl.com is the administrative API behind the Console web app, where you and your team sign in. telemetry.api.alphaagent.prometheusrl.com is the machine channel your deployments use for activation, heartbeats, usage and catalogue reads; it accepts only requests signed with a licence secret.

What the Console holds about you​

Data classFieldsWhy
Your Console account and its membersAccount name and profile, member e-mail addresses and roles, invitationsSign-in and authorisation to the Console
Licence recordsLicence id, name, description, status (active, inactive, revoked), heartbeat status and miss count, last heartbeat time, Studio version, host fingerprint, deployment kind, optional allowed egress CIDRs, enforcement status, pricingIssuing and enforcing licences
Licence secretsThe HMAC signing key of each licence, in Secrets Manager only, never in a tableVerifying your deployments' requests
Heartbeat rowsOne row per five-minute period per licence: received, expected or missedThe health view and the audit
Usage receiptsOne row per model call: event kind, token counts, model id, timestamps, licence, deployment, agent, execution, conversation and run identifiers, the principal (user_id: a Cognito subject id, an API-key id or a service name), region and zone; hourly aggregates per licence and modelBilling and your usage views
Audit eventsLicence created, activated, revoked; heartbeats received and missed; usage accepted; enforcement changesThe audit trail
Marketplace recordsYour AWS account id, the agreement, hourly metering records, monthly statementsBilling through AWS Marketplace
Organisations credentialsThe identifier of the credential your Organisations install uses to sign catalogue requestsAuthenticating downloads

The Console never receives a prompt, a completion, a document, a query result, a file or an agent definition. Usage receipts are counts and identifiers; user_id is a pseudonymous subject id from your Cognito pool, not a name or e-mail address.

Where it runs​

The Console runs on AWS in the US East (N. Virginia) region, us-east-1, in an account Prometheus Research Labs operates. It is serverless: API Gateway, Lambda functions, DynamoDB tables and Secrets Manager. Licence secrets and the response signing key are in Secrets Manager in that account.

How you sign in​

Console sign-in is Auth0, a third-party identity service and a sub-processor for that purpose. The Console web app uses the Auth0 SDK; the administrative API accepts RS256 JSON Web Tokens issued by our Auth0 tenant and checks the issuer and audience on every call. Machine requests from your deployments do not use Auth0; they are signed with the licence secret.

Retention​

DataRetention
Request nonces (replay protection)Expire 600 seconds after use
Certain account, deployment-event and billing rowsCarry an expiry attribute and are removed by DynamoDB when it passes
Licence records, heartbeat rows, usage receipts, hourly aggregates, statementsRetained for billing and reconciliation for the life of your account
Audit eventsRetained in the audit table; where the audit pipeline is configured with it, an immutable copy is written to S3 with Object Lock in compliance mode for seven years

Sub-processors​

Sub-processorPurposeWhat it receives
Amazon Web ServicesHosting of the ConsoleEverything in the table above, encrypted at rest with AWS-managed keys
Auth0Console sign-inConsole members' identities and sign-in events
AWS MarketplaceBillingYour AWS account id, your agreement, and hourly quantities of billable prompt tokens

Who at Prometheus Research Labs can see what​

Operations staff use a separate operations API with its own sign-in (a dedicated Cognito user pool; every route requires its token). It exposes: the list of customer accounts and each account's detail, a licence's detail, and the actions to set an enforcement status, set pricing, revoke a licence, regenerate a token and set an account's billing state. Through it, staff see licence metadata, heartbeat status and usage totals. There is no content to see: the Console does not hold any.

Enforcement is manual. The Console's billing automation is deployed with automatic suspension off; a Marketplace event or a reconciliation that needs attention writes a marker for an operator to act on.

How to request deletion​

Write to hello@prometheusrl.com naming the Console account. The Console API has an organisation-erasure operation that cascades across every account-scoped store (account, members, licences, usage, aggregates, statements, heartbeats) and deletes the licence secrets, and per-member erasure and export operations. There is no button for organisation deletion in the Console web app today, so the request is handled by us. Your AWS Marketplace agreement is managed in AWS Marketplace, separately from the Console account.

Steps: see what we hold, from your side​

  1. Sign in to the AlphaAgent Console and open your organisation profile and members.
  2. Open a licence key: its status, heartbeat, version and fingerprint are the licence record; Usage shows the receipts as totals, by kind and by model; the audit list shows the licence events.
  3. Open Billing and statements for the Marketplace records.
  4. For a portable copy of a member's data, ask us for the export.

What you should see​

  • Usage rows made of counts and identifiers only.
  • A heartbeat history that matches your deployment's own log.
  • No document, prompt or result anywhere in the Console.

Limits​

  • The Console region is fixed by us; it is not selectable per customer.
  • Deletion is by request, not self-service, today.
  • Studio and Organisations do not depend on Auth0; a Console sign-in outage does not affect a running deployment.

If something goes wrong​

  • You cannot sign in to the Console: the Auth0 sign-in is unavailable or your member record was removed. Your deployments keep running; contact us.
  • A licence shows heartbeats you do not recognise: compare the host fingerprint with your deployment, then revoke and regenerate.