ekai · Trust Center

Trust. Security. Transparency.

Last reviewed: September 2026

At ekai, we safeguard your data with industry-best practices, clear policies, and continuous improvement — built on a self-hosted architecture that keeps your data inside your own cloud.

Our trust commitments

01

Security first

Protecting infrastructure, applications, and data with industry-leading practices.

02

Privacy & compliance

Meeting global data-protection regulations and maintaining customer data sovereignty.

03

Transparency

Openly sharing policies, audits, and security controls with our customers.

04

Continuous improvement

Ongoing monitoring, testing, and security enhancements.

05

Trusted partnerships

Working with enterprise-grade subprocessors like Recall.ai for secure data handling. View subprocessors →

Security & infrastructure

ekai is self-hosted inside your cloud environment. You keep control of the infrastructure; we bring the controls, monitoring, and hardening by default.

01

Infrastructure & network security

Self-hosted in customer cloud environments with comprehensive access controls, monitoring, and system hardening.

02

Application security

Secure coding standards, continuous vulnerability scanning, and third-party security assessments.

03

Encryption & data protection

TLS 1.2+ for data in transit, AES-256 at rest, with comprehensive data-lifecycle management.

04

Identity & access management

SSO integration with customer identity providers and MFA enforcement.

05

Incident response & monitoring

A formal incident-response plan with customer-initiated incident management.

06

Vulnerability & penetration testing

Continuous vulnerability scanning with independent security assessments.

07

Organizational security

Comprehensive personnel controls, asset management, and physical security measures.

08

Internal security procedures

Business continuity, change management, governance, and incident-response procedures.

Compliance & certifications

Since ekai is deployed in your environment, it leverages the compliance and security certifications already in place within your hosting infrastructure — including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR where applicable. We implement the necessary measures by default to help you maintain and support these standards.

SOC 2 Type II ISO 27001 GDPR HIPAA PCI DSS

What we share

Some material is public; deeper artifacts are available under a confidentiality agreement.

CategoryPublic / general accessGated / with permission
Certifications & attestationsSecurity overview, compliance statusFull audit reports, detailed assessments
Policies & proceduresPrivacy policy, security overviewInternal control manuals, architecture diagrams
Security practicesEncryption standards, access controlsPenetration-test reports, threat models
Status & incidentsSystem status, incident summariesDetailed postmortem reports

Frequently asked security questions

What encryption do you use?+
All data in transit is protected with TLS 1.2 or higher, and data at rest is encrypted with AES-256. Keys are managed through AWS Key Management Service and can be customer-controlled, so you hold ultimate control over your encryption keys.
How do you handle data deletion?+
Because ekai runs inside your own environment, your data never leaves your control. We maintain established data-retention and disposal procedures, and customer data is deleted upon service exit. Data is classified and access is restricted to authorized personnel throughout its lifecycle.
What is your backup and disaster-recovery plan?+
Business-continuity and disaster-recovery plans are documented and regularly tested, and data-backup procedures are in place. As ekai is deployed within your infrastructure, backup and recovery align with your environment's own DR posture, keeping data inside your perimeter.
How often do you perform security audits?+
We conduct annual security reviews and hardening assessments, run continuous vulnerability scanning, and commission independent assessments and regular penetration testing through our third-party partner, we45.
What happens in case of a data breach?+
We follow formal incident-response procedures with customer-initiated incident management and a 24-hour SLA for enterprise support. Comprehensive logging and monitoring support rapid detection, investigation, and notification in line with our incident-response plan.
Who are your third-party sub-processors?+
Because ekai self-hosts within your environment, sub-processor exposure is minimal. Recall.ai is used for secure meeting-data handling — see our subprocessors page for data types, retention, and deletion details, including Recall's own Trust Center.
How does self-hosting affect compliance?+
ekai leverages the compliance and certifications already in place in your hosting infrastructure — such as SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR where applicable. Data sovereignty is maintained within your environment, and we implement supporting controls by default.
What monitoring and logging capabilities do you provide?+
We provide intrusion detection, comprehensive log management, infrastructure monitoring with real-time alerts, and automated security monitoring across production systems.
What personnel security controls do you have in place?+
All personnel with access to production systems undergo background checks. We require security-awareness training, annual performance evaluations, a code of conduct, and confidentiality agreements, with prompt access revocation upon termination.
How do you manage business continuity and disaster recovery?+
Business-continuity and disaster-recovery plans are documented and tested, backed by data-backup procedures and cybersecurity insurance coverage.
What change-management procedures do you follow?+
Change management is authorized, documented, and reviewed, with production deployment restrictions and testing requirements to keep changes controlled and auditable.
How do you handle data retention and disposal?+
We maintain established data-retention and disposal procedures. Data is classified with access restricted to authorized personnel, and customer data is deleted upon service exit.
What asset and device management controls are in place?+
Production inventory is maintained and regularly updated. We enforce portable-media encryption and mobile device management (MDM), along with visitor sign-in, badge requirements, and escorted access to secure areas.

Contact the security team

Security
tech@yourekai.com

For security inquiries and incident reporting.

Support
hello@yourekai.com

General support and technical questions.

Ready to regain control of your data?

Private AI for regulated teams. Deploy ekai in your own cloud today.

Start free →