Compliance, security, privacy, and governance for the customer execution layer, ready for your procurement review on day one.
Independently audited controls covering security, availability, and confidentiality. Report available under NDA.
Full compliance with EU General Data Protection Regulation. DPA available pre-contract.
End-to-end encryption in transit (TLS 1.3) and at rest (AES-256). Per-tenant keys.
How customer data is protected, processed, and isolated.
Integrate with Okta, Azure AD, Google Workspace, Ping Identity, OneLogin, and others.
Granular permissions per role, per team, per data scope. Audit every access.
Automated provisioning and de-provisioning via SCIM. Quarterly access review.
Every agent action, every override, every escalation, captured and searchable.
Every agent decision, system action, human override, and configuration change.
Live dashboards for conversation volume, agent latency, escalation rate, sentiment.
Trigger alerts on anomalies: volume spikes, sentiment drops, integration failures.
The third-party providers that process customer data on Ephanti's behalf.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Cloud hosting and infrastructure | US / EU / India |
| Microsoft Azure | Cloud hosting (enterprise customers) | US / EU |
| OpenAI / Anthropic / Google | Foundation model inference (configurable) | US / EU |
| Twilio | SMS and voice channels | Global |
| Datadog | Observability and monitoring | US |
| Sentry | Error monitoring | US |
Full subprocessor list available in the DPA. Notification provided 30 days before any change.
Available under NDA via your account team.
Standard GDPR-compliant DPA. Customised versions available for enterprise tier.
Full independently audited controls report. Available under NDA.
Architecture, controls, encryption, identity, audit. Available on request.
Security, compliance, and data protection questions
Yes. Ephanti has independently audited SOC 2 Type I controls covering security, availability, and confidentiality. The SOC 2 report is available under NDA as part of the procurement process.
Yes. Ephanti is compliant with the EU General Data Protection Regulation (GDPR) and provides a Data Processing Agreement (DPA) before contract execution to support customer compliance requirements.
Ephanti protects customer data through TLS 1.3 encryption in transit, AES-256 encryption at rest, logical tenant isolation, configurable data residency, encrypted backups, vulnerability scanning, penetration testing, a bug bounty program, and role-based access controls.
No. Ephanti does not use customer data to train foundation AI models without explicit customer consent. Customers retain ownership of their data, while Ephanti acts as a data processor in accordance with applicable agreements.
Ephanti supports SAML 2.0 and LDAP for single sign-on (SSO), with integrations for leading identity providers including Okta, Microsoft Entra ID (Azure AD), Google Workspace, Ping Identity, and OneLogin.
Ephanti offers configurable data residency options across the United States, European Union, and India, enabling organizations to meet regional regulatory and business requirements.
Yes. Ephanti maintains comprehensive audit logs for AI agent actions, user activities, configuration changes, and human overrides, helping organizations support governance, compliance, and security reviews.
Ephanti maintains 24/7 security monitoring, documented incident response procedures, annual disaster recovery exercises, and customer breach notification processes aligned with applicable regulatory requirements.
Yes. Organizations can request security documentation, including the SOC 2 Type I report, Data Processing Agreement (DPA), security white paper, and other procurement-related documents. Certain documents are provided under a non-disclosure agreement (NDA).
Pre-contract security reviews, custom DPA negotiations, vendor risk questionnaires. We handle them all.