Trust center

Security & Compliance

eworks.cloud is built for teams that have to answer hard questions from legal, risk and procurement before they can put an AI platform in production. This section documents how the platform is secured, which regulations it maps to, where data lives, what is audited, and how incidents are handled.

Everything described here is implemented today in the beta environment.

What is covered

PageWhat you will find
Security architectureDefense-in-depth model, authentication, authorization, encryption, network and API security, monitoring
ComplianceLGPD, GDPR and SOC 2 Type II control mappings with evidence links
Data residencyStorage regions, regional enforcement, replication, shared responsibility matrix
Audit trailAudited event types, 7-year retention, immutability, export formats, real-time alerts
Incident responseReporting channels, response timelines, forensics, customer communication

Security at a glance

ControlStatus
SSO federation (SAML 2.0, OIDC)Available on all workspaces
MFA (TOTP, passkey, YubiKey / U2F)Enforceable per workspace
Encryption at restAES-256, managed keys
Encryption in transitTLS 1.3
Tenant isolationRow-level security on every tenant-scoped table
Audit retention7 years, append-only
DSAR SLAUnder 7 days
Breach notificationUnder 72 hours
Third-party penetration testAnnual

Live dashboards

  • Compliance dashboard — e.dash at https://dash.eworks.cloud/compliance
  • Audit log explorer — e.audit at https://audit.eworks.cloud
  • Identity and MFA settings — e.identity at https://id.eworks.cloud/settings/security

Documents

SOC 2 Type II report, the Data Processing Agreement template and the security white paper are released under NDA. Request them from security@eworks.cloud or from the Trust panel in e.dash.