Trust center
Security & Compliance
eworks.cloud is built for teams that have to answer hard questions from legal, risk and procurement before they can put an AI platform in production. This section documents how the platform is secured, which regulations it maps to, where data lives, what is audited, and how incidents are handled.
Everything described here is implemented today in the beta environment.
What is covered
| Page | What you will find |
|---|---|
| Security architecture | Defense-in-depth model, authentication, authorization, encryption, network and API security, monitoring |
| Compliance | LGPD, GDPR and SOC 2 Type II control mappings with evidence links |
| Data residency | Storage regions, regional enforcement, replication, shared responsibility matrix |
| Audit trail | Audited event types, 7-year retention, immutability, export formats, real-time alerts |
| Incident response | Reporting channels, response timelines, forensics, customer communication |
Security at a glance
| Control | Status |
|---|---|
| SSO federation (SAML 2.0, OIDC) | Available on all workspaces |
| MFA (TOTP, passkey, YubiKey / U2F) | Enforceable per workspace |
| Encryption at rest | AES-256, managed keys |
| Encryption in transit | TLS 1.3 |
| Tenant isolation | Row-level security on every tenant-scoped table |
| Audit retention | 7 years, append-only |
| DSAR SLA | Under 7 days |
| Breach notification | Under 72 hours |
| Third-party penetration test | Annual |
Live dashboards
- Compliance dashboard — e.dash at
https://dash.eworks.cloud/compliance - Audit log explorer — e.audit at
https://audit.eworks.cloud - Identity and MFA settings — e.identity at
https://id.eworks.cloud/settings/security
Documents
SOC 2 Type II report, the Data Processing Agreement template and the security white paper are released under NDA. Request them from security@eworks.cloud or from the Trust panel in e.dash.
Related reading
Security architecture9 minDefense-in-depth model of eworks.cloud: SSO federation, MFA, RBAC and ABAC, tenant isolation, AES-256 and TLS 1.3 encryption, network and API security, monitoring thresholds.Compliance: LGPD, GDPR, SOC 210 minControl mappings for LGPD, GDPR and SOC 2 Type II — consent, DSAR under 7 days, right to erasure, lawful basis, DPA, 72-hour breach notification, CC9.1 and CC7.1 evidence.Data residency6 minWhere eworks.cloud stores workspace data: US and EU regions, regional GDPR and LGPD enforcement, residency selection at onboarding, replication policies and the shared responsibility matrix.Audit trail8 minAudited event types, 7-year immutable retention, hash-chained integrity, encryption, JSON/CSV/PDF export for DSAR, and real-time alerts for suspicious activity.Incident response8 minHow to report a security issue to eworks.cloud, response timelines (detection under 1h, containment under 4h, notification under 72h), forensics, customer communication and secure development practices.