Security at Eve-AI

Security is the foundation of everything we build. Here is how we protect your organization’s data.

Encryption

All data is encrypted in transit using TLS 1.2 or higher. Stored credentials — SSO client secrets, connected-account OAuth tokens, and organization API keys — are encrypted at rest at the application layer; database-level encryption at rest is provided by our managed database infrastructure.

Access Controls

Every record is scoped to your organization and enforced on every query. Organizations have admin and member roles; sensitive settings (API keys, integrations, SSO) are restricted to admins. Multi-factor authentication (TOTP) is available for all user accounts, with account-level lockout against brute-force attempts.

Infrastructure

Eve-AI runs on hardened cloud infrastructure with continuous monitoring, intrusion detection, and automated alerting. We conduct regular vulnerability assessments and third-party penetration tests.

Responsible Disclosure

If you discover a security vulnerability, please report it to security@eve-ai.com. We will acknowledge your report within 48 hours and work with you to address the issue promptly.

Compliance

We are building our security programme toward SOC 2 and ISO 27001 alignment, using the NIST CSF as our guiding framework. Formal certification is on our roadmap; contact us for our current security documentation and control status.

Contact

Security questions: security@eve-ai.com