Security at EKOM
How we protect the data you share with us — across both our website and the EKOM platform — and how to report a security concern.
The product your clients use.
The EKOM platform — the product clients use to analyze and resolve their catalogs — operates under a separate, enterprise security architecture. EKOM is the resolution layer for product data: it reconciles a catalog across the systems that describe it into one accurate record, and keeps it current everywhere it is read.
You decide how much access, if any.
Deep, standing access to your environment is not a requirement to use EKOM. You choose how much access we have — and you can start at any level and change it at any time. Across every option, the same controls apply, and there is no standing or open-ended access to your systems.
| Option | What it means |
|---|---|
| You send us data — no system access | You provide data on your terms: secure upload or a scheduled file drop. Nothing in your environment is ever exposed to us. |
| You grant scoped, read-only access | For automation, you issue least-privilege, read-only credentials scoped to only the data in question — revocable at any time. No write access to your systems. |
| Your systems push only what you choose | Your systems send us only what you select, rather than us reaching in. Your team controls exactly what leaves your perimeter. |
The controls behind every option.
| Control | Description |
|---|---|
| Data encryption | Encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent). |
| Tenant isolation | Per-organization isolation. Each client's catalog is logically isolated at the application and database layer, so one organization's data is never served to another. |
| Access control | Role-based access on a least-privilege basis. Multi-factor authentication on administrative and infrastructure access. Single sign-on via Google; SAML SSO on our roadmap. |
| Hosting & residency | Operated on AWS, with physical security inherited from AWS. A managed web application firewall (AWS WAF) and network DDoS protection (AWS Shield) sit in front of the Services. The Services are operated from, and data is processed in, the United States. |
| Monitoring & logging | Centralized application logging and monitoring, with audit logging of data-change events. |
| Vulnerability management | Dependency monitoring with remediation. Independent third-party penetration testing is planned ahead of general availability. |
| Incident response | Documented incident-response plan; affected clients notified without undue delay and, where required, within 72 hours of confirmation — consistent with GDPR Article 33. |
| Data intake | Data is provided over an encrypted channel by secure file upload, never by email. |
| Retention & deletion | Data is returned and/or securely deleted within 30 days of contract termination. |
Your data is never used to train models.
This is a firm commitment. Information you share with EKOM is used only to deliver the service to you. It is not used to train AI models, it is not shared with other customers, and it is not made public.
No client content is used to train or fine-tune any model — EKOM's or a third party's — and never across clients. Platform AI inference runs through Anthropic's Claude API under a zero-data-retention arrangement: inputs and outputs are processed for real-time inference only, and are not retained or used for training. Your catalog operates in a private mode for your account, not a shared or public one.
A small, bound set of subprocessors.
EKOM works with a small set of established subprocessors, each bound by data-protection terms. AI providers process data for real-time inference only and are not permitted to train on client content. The complete list is maintained in our Data Processing Addendum (DPA).
| Subprocessor | Purpose |
|---|---|
| Anthropic, PBC | AI inference (real-time catalog analysis) via the Claude Messages API. Zero-data-retention arrangement; not used to train models. |
| Amazon Web Services, Inc. | Application hosting and compute, object storage (S3), caching, and the managed web application firewall (AWS WAF). |
| MongoDB, Inc. (MongoDB Atlas) | Primary application database. |
| Functional Software, Inc. (Sentry) | Application error monitoring and performance telemetry. |
All subprocessors process data in the United States.
How this website treats your data.
This is separate from the platform above. Information you share through our site — form submissions (name, email, company) and chat conversations — is transmitted over an encrypted channel (TLS 1.2+) to EKOM's AWS-hosted backend, an access-controlled managed database. It is accessible only to authorized EKOM staff, who authenticate via Google single sign-on; access is role-based and isolated at the database layer (row-level security), with least-privilege credentials stored in AWS (KMS-encrypted). You may request deletion of your data at any time at security@ekom.ai.
Visitor insight
With your consent, we use IP-level company identification and B2B enrichment to tailor our response. We do not sell your data or use it for third-party advertising; we share it only with the subprocessors listed below, who process it on our behalf under contract.
AI
Chat responses are generated via Anthropic's Claude API under a zero-data-retention arrangement — inputs are processed for real-time inference only, are not retained by Anthropic, and are never used to train models.
Website subprocessors
Cloudflare (edge / CDN + WAF), Amazon Web Services (hosting + database), Anthropic (AI inference), Apollo.io (B2B enrichment), RB2B (visitor identification), and LinkedIn, Google Analytics, and Microsoft Clarity (analytics & advertising). A current list with purpose and location is maintained in our Data Processing Addendum (DPA).
Infrastructure
The site is served through Cloudflare's global edge network (TLS 1.2+, WAF); our application and data services run on AWS in the United States (us-west-2).
For how we use cookies, your analytics and advertising choices, and your privacy rights — including CPRA and Global Privacy Control (GPC) — see our Privacy Policy.
Who can reach our systems.
Access to EKOM's internal systems is restricted to authorized personnel. We use service accounts with the minimum required permissions. API keys and credentials are stored as encrypted secrets and are never exposed in source code or logs.
Report a vulnerability.
If you believe you have found a security vulnerability in our website or services, we ask that you report it to us privately before disclosing it publicly. We investigate all reports and respond within 5 business days.
Email security@ekom.ai with a description of the issue, steps to reproduce, and your contact information. We will acknowledge receipt and keep you informed as we investigate. We do not currently operate a formal bug bounty program, but we take every report seriously and will credit researchers who disclose responsibly.
Talk to us.
Enterprise clients may request our full Security & Compliance Overview and Data Processing Addendum (DPA) by contacting security@ekom.ai.
For security questions not covered here, contact security@ekom.ai. For general privacy and data requests, see our Privacy Policy or email privacy@ekom.ai.