Echelon AI Trust Center
We built the platform to keep your data protected from day one.
Request our SOC 2 report
Resources
SOC 2 Type 2 Report
Independent auditor's report from Prescient Assurance covering Security, Availability and Confidentiality, May 29 to August 31, 2026. Available on request under NDA.
FAQs
Is my data used to train AI models?
No. Customer data is never used to train models. Our foundation-model providers are configured for zero data retention, and PII, credentials and tokens are excluded from model prompts by policy.
How does Echelon access my ServiceNow instance?
Through a secure API connection using OAuth 2.0 with least-privilege, role-based access. Every action Echelon's agents take on your instance is logged and reviewable, and ServiceNow architects review the agents' work.
Where is my data hosted?
On AWS, in three production regions: us-west-2 (Oregon), eu-central-1 (Frankfurt) and eu-west-2 (London), each across three availability zones. Each region has its own database, encryption keys and secrets, and customer application data is not replicated across regions.
How is my data encrypted?
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Production databases are backed up daily with point-in-time recovery, and all backups are encrypted.
How will I be notified of a security incident?
Our Information Security Officer leads incident response with 24/7 escalation. Affected customers are notified within 24 hours of a confirmed breach involving their data, and every Critical and High incident gets a post-incident review.
Do you run penetration tests?
Yes. An independent third party tests the web application and production infrastructure at least once a year. Dependency, container and static analysis scanning also runs on every pull request.
How do I report a security issue?
Email [email protected]. We respond to security reports within 24 hours. Security questionnaires can go to the same address.
Subprocessors

Amazon Web Services (AWS)
Cloud hosting and production infrastructure

Anthropic
AI model provider, configured for zero data retention

Braintrust
AI evaluation and observability

Descope
AI evaluation and observability

PostHog
Product analytics and event tracking
Monitoring
Continuously monitored by Secureframe
Compliance

SOC 2
SOC 2 Type 2 examination by Prescient Assurance covering Security, Availability and Confidentiality. Audit period May 29 to August 31, 2026; report issued September 25, 2026.
