Security & governance
Ekamize doesn't just store your business — it runs the parts you let it. That only works if every autonomous action is permissioned, previewed and reversible. Governance isn't a feature bolted on the side; it's the spine the whole platform is built around.
Ekamize is a young company. We are not yet SOC 2 or ISO 27001 certified — and we'll say so plainly until we are. Everything below is what is true today, not a roadmap.
Six controls stand between an agent and your data.
Policy gate
Every agent action is checked against your permissions and policies before it runs. An agent never attempts what its caller isn't allowed to do.
Preview & approval
Consequential work is drafted first. You — or the right approver — see exactly what will happen and confirm before anything commits. Agents don't auto-fire.
72-hour undo
A 72-hour window to reverse actions the system took on your behalf. Mistakes stay recoverable instead of becoming permanent.
Full audit trail
Every sensitive action — exports, deletions, role changes, agent runs — is logged with who did it, what changed and when.
Watchdog agents
Supervisory agents watch for anomalies and out-of-policy behaviour across the workspace, so the system keeps itself honest.
Autonomy dial
You decide how much each agent can do on its own — from suggest-only to fully autonomous — per capability. Turn it up as trust builds.
What's true about your data.
- Encrypted in transit
- TLS 1.2+ on all traffic between you, our services and integrations.
- Encrypted at rest
- AES-256 for stored data. Secrets are held in platform-native vaults, never in code.
- Org-isolated multi-tenancy
- Row-level isolation scoped to your organisation. One org can never read another org's data.
- Audit-logged
- Sensitive actions are recorded and reviewable — a trail your finance and ops leads can actually trust.
- DPDP-aware consent
- Personal data is handled with India's DPDP framework in mind, with consent captured where it's required.
- Your data stays yours
- We do not train models on your customer data. Your business is not our training set.
- Two-factor authentication
- 2FA is available on accounts, alongside role-based permissions on every surface.
Access & accounts
Role-based permissions gate every app, action and record. Sensitive operations — exports, deletions, role changes — are audit-logged. Two- factor authentication is available, and single sign-on for larger teams is on the near roadmap.
Responsible disclosure
Found something? Email security@ekamize.com and we'll respond within 48 hours. For anything else, the founder reads dvv@ekamize.com directly. We credit reporters who help us keep Ekamize safe.