AI Employee Platform · Security & data

Your company's data, kept apart and in your hands.

The platform holds your customers, deals and money, and gives AI agents access to them. Here is exactly how it keeps each company separate, keeps keys secret and lets you leave with everything. This page only describes controls that exist today.

Start free 14-day trial

Each company's data is kept apart

  • Every record belongs to exactly one organization, down to roles, settings, files and API keys.
  • The database enforces it: row-level security lets a request see and change only its own organization's rows, even if application code forgets a filter.
  • The API checks it again. A record from another organization answers "not found", exactly like a record that doesn't exist.
  • Records can only point to records in the same organization, and only members can own, be assigned or be mentioned.
  • Files are stored under your organization, and each upload is checked against it.

Tested before every release

  • An automated test fills a second company with data, then tries to reach it through every API route and every agent tool.
  • It runs twice: with the database protection on, and with it switched off, so the application's own checks are proven on their own.
  • A new route or table is covered automatically. If the test fails, the release doesn't ship.

Agents follow the same rules as people

  • An agent is a member of one organization, with a role and permissions per module, like a person.
  • Its key and connector work for that one agent in that one organization only.
  • Hosted runs get a short-lived key for each run, which is revoked when the run ends, and go through the same checks as every other request.
  • Trust levels and daily limits are enforced by the platform on every request, whatever the AI decides.

Your AI key stays secret

  • Your Anthropic API key is encrypted with AES-256-GCM. The master key lives only in the server's environment, never in the database, so a database copy holds nothing usable.
  • Each encrypted key is bound to your organization; copied into another organization, it can't be decrypted.
  • After you save it, only its last 4 characters are ever shown. It is removed from logs and error reports.
  • Replace or delete it at any time.

Your data, to take or to delete

  • The Owner can export every record of the organization as one JSON file or as a ZIP of CSV files, at any time, even after the trial ends. Passwords and keys are never included.
  • The Owner can delete the organization. The platform cancels the subscription first, then removes every record, your files and your agents' accounts.
  • Database backups are kept for 30 days and then overwritten, so deleted data is gone from them after that.

Access and limits

  • Roles and permissions per organization: a person can be Owner in one company and Viewer in another.
  • Switch off the modules you don't use; they are hidden and refused for everyone, agents included.
  • Rate limits per address, per key, per organization and per person, so one company's traffic can't slow down another's.
  • If a subscription ends, the workspace becomes read-only. Nothing is deleted until the Owner deletes it.
Inside the app

Controls you can see

Real screens from the AI Employee Platform, with a fictional demo company.

Your data

Export or delete, from Settings

Only the Owner, signed in in person, can export or delete the organization; no API key or agent can. Deleting asks you to type the organization's slug to confirm.

  • JSON or CSV, every table of your organization
  • Works while the workspace is read-only
  • The subscription is cancelled before anything is deleted
Permissions

Agents get roles like people

Give each person and each agent a role, then add or remove permissions per module. An agent sees only what its role allows.

  • Built-in roles, plus your own
  • Per-module grants and revokes for one person or agent
  • Modules your plan doesn't include are refused for everyone
Honest limits

What the platform doesn't have yet

We would rather tell you now than have you find out later.

  • Two-step sign-in (2FA) for people is not available yet.
  • There is no audit log of people's changes yet. Agents' runs are recorded, but a full change history is still to come.
  • The platform has not had an independent penetration test yet.
  • The app is in English only for now.
  • Deleting your own personal account (rather than an organization) is not self-serve yet: email us and we will do it.

Read the full terms and privacy policy on hq.aiekip.com: Terms · Privacy Policy

Enterprise

Need the platform on your own servers?

We are preparing a self-hosted edition of the AI Employee Platform for companies that have to keep their data in-house. Tell us about your setup and requirements, and we will talk it through with you.

FAQ

Security FAQ

The questions companies ask before they move their business into the platform.

No. Every record carries your organization, the database only lets a request reach its own organization's rows, and the API checks the organization again on every request. Before each release, an automated test tries to reach a second company's data through every route and agent tool, with and without the database protection.
Ready to ship?

See it with your own data

Start a free trial, import your customers and leads from CSV, and export everything again whenever you like.

14-day free trial of Business · No credit card · Export or delete at any time