Company

Built for procurement. Built for trust.

Compliance, security, privacy, and governance for the AI customer engagement platform, ready for your procurement review on day one.

Compliance and certifications

SOC 2 Type I

Independently audited controls covering security, availability, and confidentiality. Report available under NDA.

GDPR

Full compliance with EU General Data Protection Regulation. DPA available pre-contract.

Encryption

End-to-end encryption in transit (TLS 1.3) and at rest (AES-256). Per-tenant keys.

SECURITY & COMPLIANCE ARCHITECTURE ๐Ÿ›ก๏ธ SOC 2 Type I Independently audited controls Report via NDA ๐Ÿ‡ช๐Ÿ‡บ GDPR Full EU compliance DPA pre-contract Art. 15โ€“17 rights ๐Ÿ” E2E Encryption TLS 1.3 in transit AES-256 at rest Per-tenant keys ๐Ÿ”‘ SSO ยท SAML Okta ยท Azure AD Google ยท Ping SCIM provisioning โœ… Official Meta BSP WhatsApp Business API โ€” certified Verified partner
Compliance posture ready for procurement review on day one

Security architecture

How customer data is protected, processed, and isolated.

Identity and access

SSO via SAML 2.0 and LDAP

Integrate with Okta, Azure AD, Google Workspace, Ping Identity, OneLogin, and others.

Role-based access control

Granular permissions per role, per team, per data scope. Audit every access.

Service account lifecycle

Automated provisioning and de-provisioning via SCIM. Quarterly access review.

Data handling

Audit and monitoring

Every agent action, every override, every escalation, captured and searchable.

Full audit logs

Every agent decision, system action, human override, and configuration change.

Real-time monitoring

Live dashboards for conversation volume, agent latency, escalation rate, sentiment.

Configurable alerting

Trigger alerts on anomalies: volume spikes, sentiment drops, integration failures.

Subprocessors

The third-party providers that process customer data on Ephanti's behalf.

ProviderPurposeRegion
Amazon Web ServicesCloud hosting and infrastructureUS / EU / India
Microsoft AzureCloud hosting (enterprise customers)US / EU
OpenAI / Anthropic / GoogleFoundation model inference (configurable)US / EU
TwilioSMS and voice channelsGlobal
DatadogObservability and monitoringUS
SentryError monitoringUS

Full subprocessor list available in the DPA. Notification provided 30 days before any change.

Incident response and SLAs

Documentation downloads

Available under NDA via your account team.

Data Processing Agreement (DPA)

Standard GDPR-compliant DPA. Customised versions available for enterprise tier.

SOC 2 Type I report

Full independently audited controls report. Available under NDA.

Security white paper

Architecture, controls, encryption, identity, audit. Available on request.

Need to talk to the security team?

Pre-contract security reviews, custom DPA negotiations, vendor risk questionnaires. We handle them all.

Contact security teamRequest SOC 2 report โ†’