Trust center
Last reviewed 4 September 2026
How ekai is built so you can hand it the board numbers, the cap table, and the hard people conversations.
Your perimeter
Every rival is a tenant on someone else's servers. ekai is a resident in yours. It deploys inside your own AWS, GCP, or Azure account, and your data never leaves it, not even to us.
The hosted trial is the one exception, and we state it plainly rather than bury it. The trial processes a single meeting and one calendar read on our infrastructure, then deletes it. Everything else on this page describes the deployed product.
- Self hosted by design. Your account, your bill, your control.
- Your model. Claude via Bedrock, OpenAI, or bring your own, including open weight on your own hardware.
- Nothing leaves. No vendor sees it. No third party stores it. It is never used to train a model.
- Tear it down and the context goes with it. There is no copy anywhere else.
Infrastructure and network security
Self hosted in your cloud environment, with access controls, monitoring, and system hardening.
- You retain full control of the infrastructure.
- Network segmentation and firewall protection.
- DDoS protection and monitoring.
- AWS WAF implemented with Defang.
- Unique authentication and MFA for all production systems.
- Authorized access controls for databases, operating systems, and network components.
- Prompt access revocation when personnel leave.
- Encrypted remote access with mandatory MFA.
- Intrusion detection and log management.
- Infrastructure monitoring with real time alerts.
- Network and system hardening standards maintained.
- Annual security reviews and hardening assessments.
Application security
Secure coding standards, continuous scanning, and independent assessment.
- Continuous vulnerability scanning.
- Secure coding standards and code review.
- Third party security assessments by we45.
- Automated security testing in the CI and CD pipeline.
Encryption and data protection
TLS 1.2 or higher in transit, AES-256 at rest, with data lifecycle management throughout.
- TLS 1.2 or higher for all data transmission.
- AES-256 encryption at rest.
- AWS Key Management Service integration.
- Customer controlled encryption keys.
- Data classification, with access restricted to authorized personnel.
- Data retention and disposal procedures established.
- Customer data deleted on service exit.
- Data sovereignty maintained in your environment.
Identity and access management
ekai authenticates against your identity provider rather than standing up another one.
- Single sign on integration.
- Google, Microsoft, and custom identity providers.
- Multi factor authentication support.
- Role based access control.
Incident response and monitoring
Because the data sits in your environment, you initiate incidents and we provide detection, investigation, containment, and remediation support.
- Formal incident response procedures.
- Customer initiated incident management.
- 24 hour SLA for enterprise support.
- Logging and monitoring throughout.
Vulnerability and penetration testing
Continuous scanning, with independent assessment by we45. The most recent report is published rather than gated.
- Continuous vulnerability scanning.
- Independent security assessments by we45.
- Regular penetration testing.
- Automated security monitoring.
Organizational security
Personnel controls, asset management, and physical security.
- Background checks for all personnel with access to production systems.
- Security awareness training and annual performance evaluations.
- Code of conduct and confidentiality agreements.
- Production inventory maintained and regularly updated.
- Portable media encryption and mobile device management.
- Visitor sign in procedures and badge requirements.
- Escorted access to secure areas enforced.
- Physical security controls and monitoring.
Internal security procedures
Continuity, change management, and governance.
- Business continuity and disaster recovery plans documented and tested.
- Cybersecurity insurance coverage maintained.
- Authorized, documented, and reviewed change management procedures.
- Production deployment restrictions and testing requirements.
- Defined security roles and maintained security policies.
- Board oversight and regular risk assessments.
- Vendor management and third party risk assessments.
- Data backup procedures, and system change communication.
Compliance and certifications
ekai deploys into your environment, so it operates under the compliance and security certifications already in place in your hosting infrastructure. We implement the controls needed by default to help you maintain those standards.
Read each item below as a certification held by your environment, which ekai runs inside and does not weaken. SOC 2 Type II for ekai itself is in progress.
- SOC 2 Type II
- Inherited from your hosting environment.
- ISO 27001
- Information security management, inherited from your environment.
- GDPR
- Supported by deploying in region, with data residency set per deployment.
- HIPAA
- Supported where your environment is configured for it.
- PCI DSS
- Supported where your environment is configured for it.
Subprocessors
The third parties involved in running ekai, what each does, and where it sits.
Recall.ai
- Purpose
- Meeting bot that joins and captures the call
- Location
- United States
we45
- Purpose
- Independent security assessment and penetration testing
- Location
- India and United States
Defang
- Purpose
- AWS WAF configuration and edge protection
- Location
- United States
Mixpanel
- Purpose
- Product event analytics
- Location
- United States
| Subprocessor | Purpose | Location |
|---|---|---|
| Recall.ai | Meeting bot that joins and captures the call | United States |
| we45 | Independent security assessment and penetration testing | India and United States |
| Defang | AWS WAF configuration and edge protection | United States |
| Mixpanel | Product event analytics | United States |
What we share
What is published here, and what we hand over once a review is underway.
Certifications and attestations
- Published
- Security overview, compliance status
- On request
- Full audit reports, detailed assessments
Policies and procedures
- Published
- Privacy policy, security overview
- On request
- Internal control manuals, architecture diagrams
Security practices
- Published
- Encryption standards, access controls, VAPT report
- On request
- Threat models, detailed control mapping
Status and incidents
- Published
- Incident summaries
- On request
- Detailed postmortem reports
| Category | Published | On request |
|---|---|---|
| Certifications and attestations | Security overview, compliance status | Full audit reports, detailed assessments |
| Policies and procedures | Privacy policy, security overview | Internal control manuals, architecture diagrams |
| Security practices | Encryption standards, access controls, VAPT report | Threat models, detailed control mapping |
| Status and incidents | Incident summaries | Detailed postmortem reports |
Questions a security review asks
What encryption do you use?
TLS 1.2 or higher in transit and AES-256 at rest, with keys managed through AWS Key Management Service. On a deployed ekai you hold the keys.
How do you handle data deletion?
ekai is self hosted in your environment, so you control deletion and retention according to your own compliance requirements. On the hosted trial the meeting is deleted after the results are returned.
What is your backup and disaster recovery plan?
Automated backups are created with each release, monthly by default. Frequency can be set to daily or weekly to meet your requirements.
How often do you perform security audits?
Continuous vulnerability scanning, plus regular independent assessment through we45. The current report is linked above.
What happens in case of a data breach?
We maintain a formal incident response plan. Because the data sits in your environment, you initiate the incident and we provide detection, investigation, containment, and remediation support.
Who are your third party subprocessors?
Recall.ai, we45, Defang, and Mixpanel. Each is listed above with its purpose and location. Integrations with Slack, Google Workspace, and Microsoft Teams are direct, with no third party processing in between.
How does self hosting affect compliance?
ekai operates under the certifications already in place in your environment, including SOC 2, ISO 27001, HIPAA, or PCI DSS where they apply to you.
What monitoring and logging do you provide?
Logs stay in your environment. Event tracking runs through Mixpanel by default, and can be routed to CloudWatch or your own monitoring platform instead.
What personnel controls are in place?
Background checks for anyone with production access, security awareness training, confidentiality agreements, annual performance evaluations, and an enforced code of conduct.
What change management do you follow?
Changes are authorized, documented, reviewed, and tested before production deployment. Deployment is restricted, and system changes are communicated to internal and external users as appropriate.
Talk to us
Security questionnaires and architecture reviews are welcome. Write to the address below and we will schedule a session with your security lead.
Or write to hello@yourekai.com