Security & governance

Governance is
the spine.

Ekamize runs the parts you let it. Every action is permissioned, previewed and reversible.

Where we are today

We are not yet SOC 2 or ISO 27001 certified, and we'll say so plainly until we are. Everything on this page is true today.

ControlGovernance & trust

Autonomy you can
switch off.

Six controls sit between 01 and your business. You hold all six.

01

Policy gate

Nothing runs that your policy hasn’t allowed, on every tool call, by every agent.

02

Preview & approval

Money-adjacent and client-facing actions stop for a human. You see it before it leaves.

03

72-hour undo

Agent writes keep before-images. One click reverses them; anything delivered outside is labelled first.

04

Audit trail

Who asked, what ran, what changed, and the rule it ran under. Spend is metered on its own meter.

05

Watchdogs

Standing guards on the things you are afraid of: the silent lead, the slipping site, the quiet privilege creep.

06

Autonomy dial

Four levels, per process: watch, suggest, draft, act. Trust is configured, not assumed.

Data postureWhat is true about your data

Plainly stated.
Nothing implied.

Encrypted in transit
Every request between you, our services and integrations travels over HTTPS.
Secrets in a vault
Credentials and keys are held encrypted, unwrapped only in memory, never written into code.
Org-scoped tenancy
Every query is scoped to your organisation, and structural tests fail the build if a route forgets.
Audit-logged
Every agent action and every deletion is recorded, with who asked and what it touched.
DPDP-aware consent
Personal data is handled with India’s DPDP framework in mind, consent captured where required.
Yours to see, yours to clear
Read everything 01 holds about you in one request. Erase it in one. Both land in the audit trail.
Two-factor authentication
2FA on accounts, alongside role-based permissions on every surface.

Knowledge

Governed too.

Your org builds a wiki as it works. What it learns is permissioned like everything else.

Pages are permissioned

The org wiki filters page by page against your role. A page you may not see returns nothing found, so we never leak that it exists.

Personal stays personal

What 01 remembers about you is private. It reaches shared org knowledge only when someone deliberately promotes it, and only their own.

See it, or clear it

Read everything 01 holds about you in one call, or erase it in one. Both land in the audit trail.

Access

Roles gate every surface.

Permissions gate every app, action and record. Deletions and agent actions are audit-logged. 2FA is available; SSO for larger teams is on the near roadmap.

Disclosure

Found something?

Email security@ekamize.com and we respond within 48 hours. The founder reads dvv@ekamize.com directly. We credit reporters who help keep Ekamize safe.

ProofThe Watchtower

Don’t take the six
on faith.

One screen holds every agent action, its trace, and the switch.

Watchtower2 agents running now

Every agent action

  • update_lead_statusauto allowed

    Lead 4821 → site visit done

  • send_lead_emailauto allowed

    Sharma 3BHK · follow-up 2 of 4

  • prepare_presentationauto allowed

    Mehta villa · client deck

  • raise_poheld for approval

    Ply & hardware · ₹4,80,000

  • share_file_with_clientrefused

    Internal costing sheet

That action, opened

Who asked
Priya K · Sales
What ran
send_lead_email
What changed
One mail out · activity logged on the lead
What it took
1,180 ms
The rule it ran under
Client-facing sends → allowed inside Priya’s grant
Undo it72 hours to change your mind
Credits this month 4,120Stop this agent Stop all of them

The feed

Every tool call an agent makes is written down, allowed or refused.

The trace

Open one and read the whole chain it ran, in order, with the rule.

The switch

Stop one agent, or stop all of them. It bites mid-run, not next login.

Before you trust it

Ask the hard
questions.

Request a call back

We answer security questions on the call, not in a brochure.