Enoki is present at San Francisco Tech WeekOct 5 – Oct 11

Security

We hold our own platform to the standard we hold yours.

Security is the foundation of what we sell, so we apply it to ourselves first. Enoki is built to recognized standards, and we handle customer data with the controls and care those standards require.

  • GDPRCompliant
  • ISO 27001Implementing

Where account data is stored

Your account data is stored in the European Union: Google Cloud in region europe-west1, and Supabase in Ireland. Some of our providers are based outside the EU; where personal data is transferred outside the EU or EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

A current list of our subprocessors is available on request at privacy@enokilabs.ai.

How we protect it

  • Encryption in transit (TLS), managed secret storage, and access limited to authorized staff.
  • API keys are scoped to one workspace and to the scopes you grant. A key is shown in full once, and you can rotate or revoke it.
  • Deliveries to your own webhook endpoint are signed with HMAC-SHA256 over a timestamp and the body, so you can reject forged deliveries and stale replays. Slack notifications are not signed.
  • We do not sell your data or use it for advertising. Our product analytics sets no cookies and never receives the address of an agent you test, a credential, or the content of a prompt, response or finding.

What a test does to your agent

It gets attacked, genuinely. A run only ever starts against an endpoint someone in your workspace registered, and we validate that endpoint before anything runs against it.

The attacker is broad on purpose. It does not stay on the address you gave it, and it can change or delete what it reaches, not only read it. It also tries to reach data that is not yours to see, such as another user’s or another tenant’s. A successful read is kept as proof.

Which means if you point us at a system holding real customer data, one of your customers’ records can end up in a finding, and a write that gets through changes real data. Give us a test environment with synthetic data, or accept that deliberately rather than by default.

A run is cut off after a few hours, and your workspace has a daily limit on starting them. Any member of your workspace can start a run, replay an attack and close a finding. A run can be stopped from the dashboard, from the API, or from your coding agent over MCP, and it winds down in about five seconds.

What we keep, and for how long

Every finding keeps its proof: the request, the response, and a replay script that re-runs the attack. Whatever an attack retrieves ends up in that record, and it has to, because it is how a fix gets re-verified later instead of taken on trust.

Credentials get the strongest handling we have. What matters on your side is the instruction you would give any external tester: give us a credential you can revoke, and scope it as narrowly as your agent allows.

We keep your data for as long as your account is active. To delete your account and its data, email privacy@enokilabs.ai; we remove it within 30 days, except where we must keep limited records to meet a legal obligation.