Epafi
The MachineEngineFeaturesPricingAbout
Sign inStart free
EPAFILegal

Security,by default.

Contact data is some of the most sensitive data a company holds. This page documents exactly how we protect it — controls we run today, not aspirations. Audits and pentest summaries are available under NDA.

Effective · 2026-08-01Version · 2.4Reading time · 6 min

Contents

01Encryption02Access control03Infrastructure04How we build05Incident response06Responsible disclosure
01

Encryption

  • +In transit — TLS 1.2+ everywhere; TLS 1.3 preferred. HTTP is redirected, HSTS is enforced, and API endpoints reject plaintext.
  • +At rest — AES-256 for all databases, object storage, and backups. Volumes are encrypted at the infrastructure level and application-level field encryption protects credential material.
  • +Secrets — API keys are stored hashed; we can verify them but never read them back. Third-party OAuth tokens are encrypted with a dedicated key hierarchy.
02

Access control

Internally, production access follows least privilege with hardware-key MFA, just-in-time elevation, and full audit logging. No standing production database access exists for any engineer.

For your workspace: role-based access (owner, admin, member), per-key API scopes, workspace-level SSO on Enterprise, and complete audit trails for merges, exports, and deletions.

03

Infrastructure

LayerControl
HostingAWS eu-central-1 (Frankfurt); no workspace data leaves the EU
IsolationDedicated VPC, private subnets for data stores, no public database endpoints
BackupsEncrypted, daily, 30-day retention, restore-tested monthly
MonitoringCentralized logs, anomaly alerting, 24/7 on-call rotation
AvailabilityMulti-AZ deployment; 99.99% trailing-12-month uptime
04

How we build

  • +Every change passes code review and automated security scanning (dependencies, secrets, static analysis) before merge.
  • +Staging environments use synthetic data only — customer data never leaves production.
  • +Matching-model updates are evaluated against a frozen benchmark set before rollout; regressions block deploys automatically.
  • +Dependencies are pinned, scanned daily, and patched on a severity-based schedule: critical within 72 hours.
05

Incident response

We run a documented incident process: detect, contain, eradicate, recover, review. Every incident gets a blameless postmortem; material ones get a customer-facing summary.

If a breach affects your workspace data, we notify affected workspace owners without undue delay and within 72 hours where GDPR applies — with what happened, what was affected, and what we are doing about it.

06

Responsible disclosure

We welcome security research. Report vulnerabilities to security@epafi.app — we acknowledge within 24 hours and aim to resolve critical issues within 7 days.

  • +Scope: epafi.app, api.epafi.app, and the epafi-cli package.
  • +Please do not access other customers’ data, degrade service, or spam endpoints.
  • +We do not pursue legal action against good-faith researchers who follow this policy.

Questions about this document? legal@epafi.app — we answer legal mail within two business days.

Epafi

Contact data infrastructure for teams that can’t afford a messy CRM.

All systems operational

Product

  • Features
  • The engine
  • Pricing
  • CLI

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Security
  • GDPR

Epafi

© 2026 EPAFI — ALL RIGHTS RESERVED

MADE FOR CLEAN DATA