Company

Built for procurement. Built for trust.

Compliance, security, privacy, and governance for the customer execution layer, ready for your procurement review on day one.

Compliance and certifications

SOC 2 Type I

Independently audited controls covering security, availability, and confidentiality. Report available under NDA.

GDPR

Full compliance with EU General Data Protection Regulation. DPA available pre-contract.

Encryption

End-to-end encryption in transit (TLS 1.3) and at rest (AES-256). Per-tenant keys.

SECURITY & COMPLIANCE ARCHITECTURE ๐Ÿ›ก๏ธ SOC 2 Type I Independently audited controls Report via NDA ๐Ÿ‡ช๐Ÿ‡บ GDPR Full EU compliance DPA pre-contract Art. 15โ€“17 rights ๐Ÿ” E2E Encryption TLS 1.3 in transit AES-256 at rest Per-tenant keys ๐Ÿ”‘ SSO ยท SAML Okta ยท Azure AD Google ยท Ping SCIM provisioning โœ… Official Meta BSP WhatsApp Business API โ€” certified Verified partner
Compliance posture ready for procurement review on day one

Security architecture

How customer data is protected, processed, and isolated.

Identity and access

SSO via SAML 2.0 and LDAP

Integrate with Okta, Azure AD, Google Workspace, Ping Identity, OneLogin, and others.

Role-based access control

Granular permissions per role, per team, per data scope. Audit every access.

Service account lifecycle

Automated provisioning and de-provisioning via SCIM. Quarterly access review.

Data handling

Audit and monitoring

Every agent action, every override, every escalation, captured and searchable.

Full audit logs

Every agent decision, system action, human override, and configuration change.

Real-time monitoring

Live dashboards for conversation volume, agent latency, escalation rate, sentiment.

Configurable alerting

Trigger alerts on anomalies: volume spikes, sentiment drops, integration failures.

Subprocessors

The third-party providers that process customer data on Ephanti's behalf.

ProviderPurposeRegion
Amazon Web ServicesCloud hosting and infrastructureUS / EU / India
Microsoft AzureCloud hosting (enterprise customers)US / EU
OpenAI / Anthropic / GoogleFoundation model inference (configurable)US / EU
TwilioSMS and voice channelsGlobal
DatadogObservability and monitoringUS
SentryError monitoringUS

Full subprocessor list available in the DPA. Notification provided 30 days before any change.

Incident response and SLAs

Documentation downloads

Available under NDA via your account team.

Data Processing Agreement (DPA)

Standard GDPR-compliant DPA. Customised versions available for enterprise tier.

SOC 2 Type I report

Full independently audited controls report. Available under NDA.

Security white paper

Architecture, controls, encryption, identity, audit. Available on request.

Frequently Asked Questions

Security, compliance, and data protection questions

Is Ephanti SOC 2 compliant?

Yes. Ephanti has independently audited SOC 2 Type I controls covering security, availability, and confidentiality. The SOC 2 report is available under NDA as part of the procurement process.

Is Ephanti GDPR compliant?

Yes. Ephanti is compliant with the EU General Data Protection Regulation (GDPR) and provides a Data Processing Agreement (DPA) before contract execution to support customer compliance requirements.

How does Ephanti protect customer data?

Ephanti protects customer data through TLS 1.3 encryption in transit, AES-256 encryption at rest, logical tenant isolation, configurable data residency, encrypted backups, vulnerability scanning, penetration testing, a bug bounty program, and role-based access controls.

Does Ephanti use customer data to train AI models?

No. Ephanti does not use customer data to train foundation AI models without explicit customer consent. Customers retain ownership of their data, while Ephanti acts as a data processor in accordance with applicable agreements.

Which identity providers does Ephanti support?

Ephanti supports SAML 2.0 and LDAP for single sign-on (SSO), with integrations for leading identity providers including Okta, Microsoft Entra ID (Azure AD), Google Workspace, Ping Identity, and OneLogin.

Where is customer data stored?

Ephanti offers configurable data residency options across the United States, European Union, and India, enabling organizations to meet regional regulatory and business requirements.

Does Ephanti maintain audit logs?

Yes. Ephanti maintains comprehensive audit logs for AI agent actions, user activities, configuration changes, and human overrides, helping organizations support governance, compliance, and security reviews.

How does Ephanti respond to security incidents?

Ephanti maintains 24/7 security monitoring, documented incident response procedures, annual disaster recovery exercises, and customer breach notification processes aligned with applicable regulatory requirements.

Can I request security and compliance documentation?

Yes. Organizations can request security documentation, including the SOC 2 Type I report, Data Processing Agreement (DPA), security white paper, and other procurement-related documents. Certain documents are provided under a non-disclosure agreement (NDA).

Need to talk to the security team?

Pre-contract security reviews, custom DPA negotiations, vendor risk questionnaires. We handle them all.

Contact security teamRequest SOC 2 report โ†’