Skip to content
Ektasi.
Platform / Data Sovereignty

Your data stays yours. Provably.

Sovereignty is not a checkbox on a PDF - it is an architecture. Ektasi can be self-hosted end to end, runs AI on your own hardware, isolates every tenant in the database engine, and erases a tenant's records from the live database on request. Built with India's Digital Personal Data Protection Act, 2023 in mind.

How sovereignty is enforced
01

Self-Host the Whole Platform

Ektasi ships as a single deployable codebase. Run it in your own cloud account or on your own hardware - the marketing site, the dashboard and every module in one place, under your control.

02

Keep AI on Your Network

Point the AI resolver at a self-hosted, OpenAI-compatible model (Ollama or vLLM). Sensitive prompts and documents never traverse a third-party API - inference stays inside your perimeter.

03

Tenant Isolation in the Engine

PostgreSQL Row-Level Security means a query scoped to one tenant cannot return another tenant’s rows. Isolation is enforced by the database, not by application-layer good intentions.

04

Per-Tenant Cryptography

Stored credentials are sealed with AES-256-GCM using per-tenant, HKDF-derived keys. The data-encryption key is derived, never stored - so a leaked database is not a leaked vault. Ordinary tenant rows rely on row-level isolation rather than per-tenant encryption.

05

Tenant Erasure

Decommissioning a tenant deletes every table that carries its identifier from the live database, in one transaction — if any step fails nothing is deleted — and destroys its per-tenant salt, so its stored credentials can no longer be decrypted. Two records are kept for eight financial years because tax and company law require them (CGST Act s.36; Companies Act, 2013 s.128(5), permitted by DPDP Act s.8(7)): the GST tax invoices we issued, and the record of the acceptance behind each charge. Copies in backups expire on the retention schedule of the deployment they sit in. The audit ledger keeps the proof it happened.

06

Forensic Audit Ledger

An append-only audit log, enforced by a database trigger, records key administrative actions. Evidence for a DPDP audit or a customer security review is generated as you operate.

System map · Data Sovereignty
Data Sovereigntyone postureSelf-Host the WholePlatformKeep AI on YourNetworkTenant Isolation inthe EnginePer-TenantCryptographyTenant ErasureForensic Audit Ledger
DPDP Act, 2023

Architecture that maps to your obligations.

Ektasi is engineering, not legal advice. Confirm your specific compliance posture with counsel - the platform is built to make that posture defensible.

Data residency

Deploy in-country. Personal data of Indian principals can stay on infrastructure you choose and control.

Purpose & consent

Per-tenant boundaries and audit trails support consent-linked processing and demonstrable accountability.

Right to erasure

Decommissioning removes every table that carries a tenant’s identifier from the live database and destroys its credential keys - not a soft delete. Two records are kept for eight financial years because tax and company law require them (CGST Act s.36; Companies Act, 2013 s.128(5), permitted by DPDP Act s.8(7)): the GST tax invoices we issued, and the record of the acceptance behind each charge. Backup copies expire on the deployment’s retention schedule.

Breach evidence

The append-only ledger provides the forensic record a Significant Data Fiduciary is expected to keep.

Own your platform. Own your data.

Ask us for a self-hosting walkthrough and a data-sovereignty review mapped to your regulatory reality.