epok
TRUST

Your telemetry is your data.

Production data is a meaningful trust decision. Here's how we handle yours.

CURRENT EVALUATION POSTURE

Synthetic, public, or security-approved telemetry can be evaluated immediately. Production approval depends on your requirements. Google OAuth and scoped API keys are available; Microsoft login, SAML, SCIM, and a completed SOC 2 Type II report are not.

Review the controlled evaluation plan →
01AI HANDLING

Your telemetry never trains anyone's model

Your telemetry is never used to train AI models. When AI root-cause drafting is enabled, the AI layer receives the evidence it needs — service names, error categories, timestamps, and the top error patterns and representative messages from the incident window. That content is never used for training and is not retained by the provider beyond standard abuse-monitoring windows. Statistical detection and rule packs run entirely inside our own infrastructure and never touch an external AI provider.

TRAININGYour telemetry never used for training
RETENTIONProvider-side: standard abuse window only
INPUTSIncident evidence — service, category, timestamps, top patterns + messages
DETECTIONDetectors + rule packs run in-infra · no external AI
02ENCRYPTED

Encryption boundaries stated plainly

TLS in transit, modern cipher suites only. Sensitive configuration (notification webhooks, integration credentials) is encrypted at rest. Application database runs on a managed relational backend with provider-side encryption.

TRANSITTLS · modern cipher suites · HSTS
AT RESTEncrypted webhook + integration secrets
DATABASEManaged relational backend · provider-side encryption
03ISOLATION

Tenant isolation on every query

Every read, every write, and every detection query carries account and project identifiers. Ingest streams are tenant-scoped. Concurrency limits apply per tenant so no one's workload starves another.

DATABASEAccount + project ID required on every query
INGESTPer-tenant rate limits and daily byte caps
COMPUTEConcurrency limit per tenant · no shared path
04RETENTION

Retention and deletion

Ingest pauses when the 14-day trial ends; existing data remains readable while it ages out under the 14-day retention policy. Team and Growth retain data for 30 days. Custom retention is reviewed per agreement. Tenant-scoped deletion is available on request.

TRIALIngest pauses day 15 · data ages out under 14-day retention
TEAM30 days · hard delete at expiry
GROWTH30 days · hard delete at expiry
CUSTOMPer-deal · scoped retention
GDPRTenant-scoped delete on request
05ACCESS

Access controls

Login uses Google OAuth today. Microsoft login, SAML enterprise SSO, and SCIM are not available. API keys are scoped — read, ingest, or both — and listed per tenant. Alert state changes are timestamped with an actor; a full administrative audit log is not yet available.

LOGINGoogle OAuth available · Microsoft / SAML / SCIM unavailable
API KEYSScoped: ingest · read · both · per-tenant
AUDITAlert actions recorded · full administrative audit log unavailable
06COMPLIANCE

Compliance and deployment

SOC 2 Type II is in progress — we will publish the report here when it is complete. GDPR-aligned, DPA on request. Primary infrastructure runs in the EU (Germany/Finland). Custom residency, dedicated deployment, and self-hosting require an architecture and commercial review.

SOC 2Type II in progress · report published here when complete
GDPRAligned · DPA on request
RESIDENCYEU (Germany/Finland) · other requirements reviewed case by case
DEPLOYMENTDedicated and self-hosted options require architecture review
QUESTIONNAIRESSIG / CAIQ / custom security review available on request
07SUBPROCESSORS

We publish our subprocessors

We publish the services involved in operating Epok and state the data each function receives. Most subprocessors receive account, billing, request, or product-usage metadata. When AI root-cause drafting is enabled, the model provider can receive selected incident evidence, including representative telemetry messages, as described in the AI-handling section.

INFRAEU data-center provider (Germany/Finland) — compute + storage
EDGECloudflare — CDN, DNS, DDoS, TLS (request metadata, not log content)
AUTHGoogle OAuth — name + email only
BILLINGPaddle — subscription billing (merchant of record)
OPSPostHog (analytics) · New Relic + Sentry (our own monitoring)
AI DRAFTINGModel provider — selected incident evidence when AI RCA is enabled
LISTFull, current list on the privacy page

Have a security questionnaire?

We answer SIG, CAIQ, and custom questionnaires on request. Procurement, legal, and IT teams welcome.

Contact us →