Trust & security

Security & governance

Ekamize doesn't just store your business — it runs the parts you let it. That only works if every autonomous action is permissioned, previewed and reversible. Governance isn't a feature bolted on the side; it's the spine the whole platform is built around.

Where we are today

Ekamize is a young company. We are not yet SOC 2 or ISO 27001 certified — and we'll say so plainly until we are. Everything below is what is true today, not a roadmap.

The governance spine

Six controls stand between an agent and your data.

Policy gate

Every agent action is checked against your permissions and policies before it runs. An agent never attempts what its caller isn't allowed to do.

Preview & approval

Consequential work is drafted first. You — or the right approver — see exactly what will happen and confirm before anything commits. Agents don't auto-fire.

72-hour undo

A 72-hour window to reverse actions the system took on your behalf. Mistakes stay recoverable instead of becoming permanent.

Full audit trail

Every sensitive action — exports, deletions, role changes, agent runs — is logged with who did it, what changed and when.

Watchdog agents

Supervisory agents watch for anomalies and out-of-policy behaviour across the workspace, so the system keeps itself honest.

Autonomy dial

You decide how much each agent can do on its own — from suggest-only to fully autonomous — per capability. Turn it up as trust builds.

Data posture

What's true about your data.

Encrypted in transit
TLS 1.2+ on all traffic between you, our services and integrations.
Encrypted at rest
AES-256 for stored data. Secrets are held in platform-native vaults, never in code.
Org-isolated multi-tenancy
Row-level isolation scoped to your organisation. One org can never read another org's data.
Audit-logged
Sensitive actions are recorded and reviewable — a trail your finance and ops leads can actually trust.
DPDP-aware consent
Personal data is handled with India's DPDP framework in mind, with consent captured where it's required.
Your data stays yours
We do not train models on your customer data. Your business is not our training set.
Two-factor authentication
2FA is available on accounts, alongside role-based permissions on every surface.

Access & accounts

Role-based permissions gate every app, action and record. Sensitive operations — exports, deletions, role changes — are audit-logged. Two- factor authentication is available, and single sign-on for larger teams is on the near roadmap.

Responsible disclosure

Found something? Email security@ekamize.com and we'll respond within 48 hours. For anything else, the founder reads dvv@ekamize.com directly. We credit reporters who help us keep Ekamize safe.