Trust & Security

Security at EKOM

How we protect the data you share with us — across both our website and the EKOM platform — and how to report a security concern.


Platform security

The product your clients use.

The EKOM platform — the product clients use to analyze and resolve their catalogs — operates under a separate, enterprise security architecture. EKOM is the resolution layer for product data: it reconciles a catalog across the systems that describe it into one accurate record, and keeps it current everywhere it is read.

SOC 2 Certified · 2024 Our SOC 2 report is available under NDA to qualified prospects and clients. Contact security@ekom.ai to request it.
Access model

You decide how much access, if any.

Deep, standing access to your environment is not a requirement to use EKOM. You choose how much access we have — and you can start at any level and change it at any time. Across every option, the same controls apply, and there is no standing or open-ended access to your systems.

OptionWhat it means
You send us data — no system accessYou provide data on your terms: secure upload or a scheduled file drop. Nothing in your environment is ever exposed to us.
You grant scoped, read-only accessFor automation, you issue least-privilege, read-only credentials scoped to only the data in question — revocable at any time. No write access to your systems.
Your systems push only what you chooseYour systems send us only what you select, rather than us reaching in. Your team controls exactly what leaves your perimeter.
Recommended starting point. Start by connecting your catalog — let EKOM work with it and show you what it can do, before you integrate any additional systems. Your catalog is the fastest path to seeing the platform work on your own data, with the least lift on your side.
Controls

The controls behind every option.

ControlDescription
Data encryptionEncrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
Tenant isolationPer-organization isolation. Each client's catalog is logically isolated at the application and database layer, so one organization's data is never served to another.
Access controlRole-based access on a least-privilege basis. Multi-factor authentication on administrative and infrastructure access. Single sign-on via Google; SAML SSO on our roadmap.
Hosting & residencyOperated on AWS, with physical security inherited from AWS. A managed web application firewall (AWS WAF) and network DDoS protection (AWS Shield) sit in front of the Services. The Services are operated from, and data is processed in, the United States.
Monitoring & loggingCentralized application logging and monitoring, with audit logging of data-change events.
Vulnerability managementDependency monitoring with remediation. Independent third-party penetration testing is planned ahead of general availability.
Incident responseDocumented incident-response plan; affected clients notified without undue delay and, where required, within 72 hours of confirmation — consistent with GDPR Article 33.
Data intakeData is provided over an encrypted channel by secure file upload, never by email.
Retention & deletionData is returned and/or securely deleted within 30 days of contract termination.
Data & AI

Your data is never used to train models.

This is a firm commitment. Information you share with EKOM is used only to deliver the service to you. It is not used to train AI models, it is not shared with other customers, and it is not made public.

No client content is used to train or fine-tune any model — EKOM's or a third party's — and never across clients. Platform AI inference runs through Anthropic's Claude API under a zero-data-retention arrangement: inputs and outputs are processed for real-time inference only, and are not retained or used for training. Your catalog operates in a private mode for your account, not a shared or public one.

Subprocessors

A small, bound set of subprocessors.

EKOM works with a small set of established subprocessors, each bound by data-protection terms. AI providers process data for real-time inference only and are not permitted to train on client content. The complete list is maintained in our Data Processing Addendum (DPA).

SubprocessorPurpose
Anthropic, PBCAI inference (real-time catalog analysis) via the Claude Messages API. Zero-data-retention arrangement; not used to train models.
Amazon Web Services, Inc.Application hosting and compute, object storage (S3), caching, and the managed web application firewall (AWS WAF).
MongoDB, Inc. (MongoDB Atlas)Primary application database.
Functional Software, Inc. (Sentry)Application error monitoring and performance telemetry.

All subprocessors process data in the United States.

Website & data handling

How this website treats your data.

This is separate from the platform above. Information you share through our site — form submissions (name, email, company) and chat conversations — is transmitted over an encrypted channel (TLS 1.2+) to EKOM's AWS-hosted backend, an access-controlled managed database. It is accessible only to authorized EKOM staff, who authenticate via Google single sign-on; access is role-based and isolated at the database layer (row-level security), with least-privilege credentials stored in AWS (KMS-encrypted). You may request deletion of your data at any time at security@ekom.ai.

Visitor insight

With your consent, we use IP-level company identification and B2B enrichment to tailor our response. We do not sell your data or use it for third-party advertising; we share it only with the subprocessors listed below, who process it on our behalf under contract.

AI

Chat responses are generated via Anthropic's Claude API under a zero-data-retention arrangement — inputs are processed for real-time inference only, are not retained by Anthropic, and are never used to train models.

Website subprocessors

Cloudflare (edge / CDN + WAF), Amazon Web Services (hosting + database), Anthropic (AI inference), Apollo.io (B2B enrichment), RB2B (visitor identification), and LinkedIn, Google Analytics, and Microsoft Clarity (analytics & advertising). A current list with purpose and location is maintained in our Data Processing Addendum (DPA).

Infrastructure

The site is served through Cloudflare's global edge network (TLS 1.2+, WAF); our application and data services run on AWS in the United States (us-west-2).

For how we use cookies, your analytics and advertising choices, and your privacy rights — including CPRA and Global Privacy Control (GPC) — see our Privacy Policy.

Access controls

Who can reach our systems.

Access to EKOM's internal systems is restricted to authorized personnel. We use service accounts with the minimum required permissions. API keys and credentials are stored as encrypted secrets and are never exposed in source code or logs.

Responsible disclosure

Report a vulnerability.

If you believe you have found a security vulnerability in our website or services, we ask that you report it to us privately before disclosing it publicly. We investigate all reports and respond within 5 business days.

Email security@ekom.ai with a description of the issue, steps to reproduce, and your contact information. We will acknowledge receipt and keep you informed as we investigate. We do not currently operate a formal bug bounty program, but we take every report seriously and will credit researchers who disclose responsibly.

Questions

Talk to us.

Enterprise clients may request our full Security & Compliance Overview and Data Processing Addendum (DPA) by contacting security@ekom.ai.

For security questions not covered here, contact security@ekom.ai. For general privacy and data requests, see our Privacy Policy or email privacy@ekom.ai.