Skip to content
Ektasi.
← Ektasi

Zero-Trust Architecture

Security at Ektasi is enforced by runtime constraints, not legal promises. Each layer is implemented in code and exercised by tests.

01

Edge

Per-request nonce CSP + security headers; edge-verified jose JWT sessions injected as identity headers.

02

Tenant Isolation

PostgreSQL Row-Level Security — a query from one tenant cannot return another tenant’s data.

03

Secrets

Stored credentials are encrypted with AES-256-GCM under per-tenant HKDF-derived keys; the platform KEK + per-tenant salt derive the DEK (never stored). Ordinary workspace rows are protected by RLS, not by per-tenant encryption.

04

Forensic Ledger

Append-only audit_logs enforced by a database trigger; key administrative actions write an entry.

05

AI Containment

Natural-language→SQL runs behind a fail-closed lexical gate, proven by deterministic tests on every build.

06

Erasure

Decommission deletes every table that carries the tenant’s identifier from the live database, in one transaction, and destroys the per-tenant salt, so stored credentials can no longer be decrypted from the live system. Two records are kept for eight financial years because tax and company law require them (CGST Act s.36; Companies Act, 2013 s.128(5), permitted by DPDP Act s.8(7)): the GST tax invoices we issued, and the record of the acceptance behind each charge. Backup copies expire on a rolling retention schedule.

Request a security review →