As the data controller, we ensure all partners meet or exceed our security and privacy standards. Below are the key partners we work with:

Defang.io

We leverage Defang.io as a trusted subcontractor to securely deploy the Ekai application into customer cloud accounts, in accordance with the best-practices for each target cloud (e.g. AWS, GCP, etc.). Defang is an enterprise-grade platform with robust security controls (view their Trust Center).

The Defang tool takes as input the Ekai application definition (source code, binaries, and Compose.yaml manifest) and deploys it to the target cloud account. Defang follows the principle of least privilege to ensure only the roles and permissions necessary are enabled. Defang.io (the company) has no access to the target cloud account or any data or services hosted within it. A detailed description of how Defang deploys applications to AWS can be found in this white-paper.

Security & Compliance:
  • Defang maintains SOC 2 Type II compliance and has passed 3rd-party audits for the same.
  • Defang has also gone through independent 3rd-party security audits and pen-tests in accordance with CIS (Center for Internet Security) Benchmark.
  • Additionally, Defang has worked closely with solution architects from public cloud platforms such as AWS and GCP to ensure both Defang itself and every application deployment performed using Defang conform to the best-practices corresponding to each cloud platform.

Recall.ai

We leverage Recall.ai as a trusted partner to provide secure transcript and bot media handling. Recall is an enterprise-grade platform with robust security controls (view their Trust Center).

Data Types Processed: Audio/video streams, transcripts, and related metadata generated during bot sessions.
Retention Options: Recall supports zero-day retention policies, meaning transcripts and media can be configured to never persist beyond the session.
Data Deletion:
  • We receive automatic notifications when bot sessions end.
  • Once a session is complete, our system immediately requests that all transcripts and media files be permanently deleted from Recall's servers.
Customer Control: You may request strict retention windows (including zero-day) to align with your compliance requirements.
Security & Compliance: Recall maintains SOC 2, ISO 27001, GDPR, and other industry-standard certifications.