Your telemetry is your data.
Production data is a meaningful trust decision. Here's how we handle yours.
Synthetic, public, or security-approved telemetry can be evaluated immediately. Production approval depends on your requirements. Google OAuth and scoped API keys are available; Microsoft login, SAML, SCIM, and a completed SOC 2 Type II report are not.
Review the controlled evaluation plan →Your telemetry never trains anyone's model
Your telemetry is never used to train AI models. When AI root-cause drafting is enabled, the AI layer receives the evidence it needs — service names, error categories, timestamps, and the top error patterns and representative messages from the incident window. That content is never used for training and is not retained by the provider beyond standard abuse-monitoring windows. Statistical detection and rule packs run entirely inside our own infrastructure and never touch an external AI provider.
Encryption boundaries stated plainly
TLS in transit, modern cipher suites only. Sensitive configuration (notification webhooks, integration credentials) is encrypted at rest. Application database runs on a managed relational backend with provider-side encryption.
Tenant isolation on every query
Every read, every write, and every detection query carries account and project identifiers. Ingest streams are tenant-scoped. Concurrency limits apply per tenant so no one's workload starves another.
Retention and deletion
Ingest pauses when the 14-day trial ends; existing data remains readable while it ages out under the 14-day retention policy. Team and Growth retain data for 30 days. Custom retention is reviewed per agreement. Tenant-scoped deletion is available on request.
Access controls
Login uses Google OAuth today. Microsoft login, SAML enterprise SSO, and SCIM are not available. API keys are scoped — read, ingest, or both — and listed per tenant. Alert state changes are timestamped with an actor; a full administrative audit log is not yet available.
Compliance and deployment
SOC 2 Type II is in progress — we will publish the report here when it is complete. GDPR-aligned, DPA on request. Primary infrastructure runs in the EU (Germany/Finland). Custom residency, dedicated deployment, and self-hosting require an architecture and commercial review.
We publish our subprocessors
We publish the services involved in operating Epok and state the data each function receives. Most subprocessors receive account, billing, request, or product-usage metadata. When AI root-cause drafting is enabled, the model provider can receive selected incident evidence, including representative telemetry messages, as described in the AI-handling section.
Have a security questionnaire?
We answer SIG, CAIQ, and custom questionnaires on request. Procurement, legal, and IT teams welcome.
Contact us →