Get Started

Trust at Epismo


Epismo is designed to preserve the context people and AI agents need to continue work while keeping customer data within a controlled environment. This page explains where customer data is stored and processed, how it is protected, how it is used for personalization and product improvement, and how Epismo handles AI-related features. For information about the personal information we collect and your privacy rights, please see our Privacy Policy.

Data Location

Epismo runs its production infrastructure on Google Cloud in the United States, in the us-west1 region. Search and indexing run on Elastic Cloud, also hosted on Google Cloud in the same region. Customer content, database backups, and the files you upload are stored and processed in that region. Operational logs are kept for a limited retention period and are not used to build a separate copy of customer content.

Security

All connections to Epismo are encrypted in transit, and customer data is encrypted at rest.

Access to customer data is authenticated and authorized on every request. Customer content is also not reachable from the public internet: Epismo's own production systems reach it over a private network, or from a single address we control, so a leaked credential on its own would not be enough from anywhere else.

Inside Epismo, access follows the principle of least privilege: each component is given only the access its own work needs, so a compromise in one place does not spread to the rest of your data.

Access to Your Content

Epismo enforces access rights on every request rather than only in the interface, and the same checks apply whether you reach Epismo through the web app, the API, the CLI, or an MCP client.

Content you have not been given access to is not returned to you, including in search results. Workspaces are kept separate from one another the same way.

Availability and Recovery

Epismo's database is backed up daily and supports point-in-time recovery within its retention window, so it can be restored to a specific moment rather than only to the most recent snapshot.

Large Language Models

The features Epismo operates do not send customer data to external large language model (LLM) providers. Customer data is not used to train generative AI models, and Epismo does not permit third parties to use it for that purpose.

Epismo is built to be used alongside AI tools you choose, through our API, CLI, and MCP integrations. When you connect one of those tools, it reads the data you have given it access to, under your account's permissions and under that provider's own terms. You decide which tools to connect and what they can reach.

Personalization

Epismo may process customer data within the service to provide and personalize features such as search, ranking, and recommendations for the relevant customer or workspace. This processing stays within the boundaries described above.

Product Improvement

To evaluate and improve these features and the product's overall performance, we may also use aggregated or de-identified statistics derived from customer data and product usage. These statistics are designed not to disclose customer content or identify a customer, workspace, or individual to other customers or third parties.

Third Parties

The statements above apply to customer data handled by Epismo. Payments are processed by Stripe, and Epismo does not store your card details. Information you provide directly to another company, or choose to transfer out of Epismo, is handled under that company's terms and privacy practices.

Questions

Questions about Epismo's security and data practices? Contact Support.