Trust. Security. Transparency.
Last reviewed: September 2026
At ekai, we safeguard your data with industry-best practices, clear policies, and continuous improvement — built on a self-hosted architecture that keeps your data inside your own cloud.
Our trust commitments
Security first
Protecting infrastructure, applications, and data with industry-leading practices.
Privacy & compliance
Meeting global data-protection regulations and maintaining customer data sovereignty.
Transparency
Openly sharing policies, audits, and security controls with our customers.
Continuous improvement
Ongoing monitoring, testing, and security enhancements.
Trusted partnerships
Working with enterprise-grade subprocessors like Recall.ai for secure data handling. View subprocessors →
Security & infrastructure
ekai is self-hosted inside your cloud environment. You keep control of the infrastructure; we bring the controls, monitoring, and hardening by default.
Infrastructure & network security
Self-hosted in customer cloud environments with comprehensive access controls, monitoring, and system hardening.
- Customer retains full control of infrastructure
- Network segmentation and firewall protection
- DDoS protection and monitoring
- AWS WAF implemented with Defang
- Unique authentication and MFA for all production systems
- Authorized access controls for databases, OS, and network components
- Prompt access revocation upon personnel termination
- Encrypted remote access with mandatory MFA
- Intrusion detection and comprehensive log management
- Infrastructure monitoring with real-time alerts
- Network and system hardening standards maintained
- Annual security reviews and hardening assessments
Application security
Secure coding standards, continuous vulnerability scanning, and third-party security assessments.
- Continuous vulnerability scanning
- Secure coding standards and code reviews
- Third-party security assessments by we45
- Automated security testing in the CI/CD pipeline
Encryption & data protection
TLS 1.2+ for data in transit, AES-256 at rest, with comprehensive data-lifecycle management.
- TLS 1.2+ for all data transmission
- AES-256 encryption at rest
- AWS Key Management Service integration
- Customer-controlled encryption keys
- Data classification and access restriction to authorized personnel
- Data retention and disposal procedures established
- Customer data deletion upon service exit
- Sensitive data handling protocols
- Data sovereignty maintained in customer environment
Identity & access management
SSO integration with customer identity providers and MFA enforcement.
- Single Sign-On (SSO) integration
- Google, Microsoft, and custom identity providers
- Multi-Factor Authentication (MFA) support
- Role-based access control (RBAC)
Incident response & monitoring
A formal incident-response plan with customer-initiated incident management.
- Formal incident-response procedures
- Customer-initiated incident management
- 24-hour SLA for enterprise support
- Comprehensive logging and monitoring
Vulnerability & penetration testing
Continuous vulnerability scanning with independent security assessments.
- Independent security assessments by we45 — VAPT report available on request
- Regular penetration testing
- Automated security monitoring
- ADA-CASA assessment in progress — undergoing an App Defense Alliance CASA (Level 1) security assessment for Google API restricted-scope verification
Organizational security
Comprehensive personnel controls, asset management, and physical security measures.
- Background checks for all personnel with access to production systems
- Security-awareness training and annual performance evaluations
- Code of conduct and confidentiality agreements
- Production inventory maintained and regularly updated
- Portable-media encryption and mobile device management (MDM)
- Visitor sign-in procedures and badge requirements
- Escorted access to secure areas enforced
- Physical security controls and monitoring
Internal security procedures
Business continuity, change management, governance, and incident-response procedures.
- Business continuity and disaster-recovery plans documented and tested
- Cybersecurity insurance coverage maintained
- Authorized, documented, and reviewed change-management procedures
- Production deployment restrictions and testing requirements
- Defined security roles and maintained security policies
- Board oversight and regular risk assessments conducted
- Vendor management and third-party risk assessments
- Formal incident-management policies and procedures
- Data backup procedures and system-change communication
- Support resources and service commitments communicated to customers
Compliance & certifications
Since ekai is deployed in your environment, it leverages the compliance and security certifications already in place within your hosting infrastructure — including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR where applicable. We implement the necessary measures by default to help you maintain and support these standards.
What we share
Some material is public; deeper artifacts are available under a confidentiality agreement.
| Category | Public / general access | Gated / with permission |
|---|---|---|
| Certifications & attestations | Security overview, compliance status | Full audit reports, detailed assessments |
| Policies & procedures | Privacy policy, security overview | Internal control manuals, architecture diagrams |
| Security practices | Encryption standards, access controls | Penetration-test reports, threat models |
| Status & incidents | System status, incident summaries | Detailed postmortem reports |
Frequently asked security questions
What encryption do you use?+
How do you handle data deletion?+
What is your backup and disaster-recovery plan?+
How often do you perform security audits?+
What happens in case of a data breach?+
Who are your third-party sub-processors?+
How does self-hosting affect compliance?+
What monitoring and logging capabilities do you provide?+
What personnel security controls do you have in place?+
How do you manage business continuity and disaster recovery?+
What change-management procedures do you follow?+
How do you handle data retention and disposal?+
What asset and device management controls are in place?+
Contact the security team
Ready to regain control of your data?
Private AI for regulated teams. Deploy ekai in your own cloud today.
Start free →