メインコンテンツへスキップ

Security & Privacy FAQ

Answers to common questions about how EKB protects your data, which standards we follow, and how models, access, and deployments work.

For deeper narrative coverage, see Security & Compliance and Security & Data Practices.

Compliance & standards​

Is EKB compliant with any security standards?

EKB is SOC 2 Type II and ISO 27001 compliant, and is compliant with GDPR, CCPA, and HIPAA regulations.

See Security & Compliance for details on each certification.

What security practices does EKB follow for my data?

EKB follows high standards of data security and privacy. For how your data is used, see Security & Data Practices and your organization's APA InfoSec FAQ where applicable.

Why does EKB need my information?

EKB processes data to provide the product—knowledge retrieval, agents, workflows, and related services. For why and how data is processed, see Security & Data Practices and your organization's APA InfoSec FAQ where applicable.

Models & licensing​

How does EKB train its language models for my enterprise?

EKB uses well-known commercial off-the-shelf foundational models to build AI solutions from data in your project's knowledge base and/or data uploaded in real time and via prompts. These models use your knowledge base to provide accurate, grounded responses to questions, queries, and flows.

Your data is not stored or used to train hosted models.

Can I bring my own license (BYOL) for LLMs?

Yes. You can create custom model connections using your own licensing in a bring-your-own-license (BYOL) model.

Can I run local self-hosted models?

In On-Premise deployments, you can host your own LLM and connect through OpenAI-compatible APIs to hosting stacks such as Ollama, vLLM, SGLang, and similar.

Encryption & data protection​

What type of encryption is used to secure my data?

EKB uses industry-standard AES-256 encryption to secure data.

What type of data gets encrypted?

All stored and in-flight data is encrypted.

Is TLS supported?

Yes. General connectivity uses TLS 1.2, and most hosted models employ TLS 1.3.

Where is my data stored and how safe is it?

Data is stored in an encrypted database and handled in line with current security standards. See Security & Data Practices for more on storage and handling.

Deployment & data residency​

Can the data be stored in my private cloud or On-Premise?

Yes. EKB can be deployed On-Premise in your private cloud (VPC/VNet) or on bare metal.

Is my data (or access to it) shared with anyone?

Access depends on the type of data. Personally identifiable sensitive data is accessible only to you. Personally identifiable sensitive information uploaded to the Knowledge Base is pseudonymized or anonymized. Our team only has access to information essential to providing services (for example, email).

Access, tenancy & SSO​

How is access applied?

Each instance is tied to an owner. Ownership has its own tenant ID, which is the basis for logical separation. The owner can add projects and assign roles. Each project has a team. Roles can be Admin, Editor, Viewer, or custom.

Users can sign up but cannot access anything until they are invited to a project. Users may belong to one or more projects. External communications use an app key that is either project-based or user-based.

Is SSO supported?

Yes. SAML 2.0 is supported, including Azure Entra ID (Azure AD). See SSO and related authentication docs for setup.

Retention & deletion​

Can I delete my data?

Yes. You have full control over your data and can add or remove it at any time.

How long is my data saved?

Knowledge base data is stored for as long as you keep it. You can remove it whenever you choose.

Networking & communication​

What types of communication are typical?
  • User or automation to EKB — SSL/TLS 1.2, typically port 443.
  • Internal communication — Between Docker services, the core knowledge base database (Supabase), and front-end and back-end services. These services need to communicate freely with each other.
  • External communication — Depends on deployment: Cloud (SaaS) or On-Premise (bare metal / VPC).

For security or compliance documentation requests, contact Support.