Security
How we protect your data, your agents, and your companies.
Infrastructure
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Our infrastructure runs in isolated environments with no shared tenancy between workspaces.
Agent sessions are sandboxed. Each company operates in its own isolated context — agents from one company cannot access data from another.
Authentication
All accounts are protected with JWT-based authentication. Sessions expire automatically. We enforce secure password requirements and plan to support passkeys and SSO for enterprise accounts.
Data handling
We do not train models on your data. Agent conversations are processed by third-party LLM providers strictly to generate responses. We send only the minimum data necessary.
If you bring your own API key, your data goes directly to your provider. We never see the content.
Subprocessors
| Provider | Purpose |
|---|---|
| Hetzner | Infrastructure hosting |
| Cloudflare | DNS, CDN, DDoS protection |
| OpenRouter | LLM inference routing |
| Anthropic | LLM inference |
| Kimi (Moonshot AI) | LLM inference |
On-chain data
If you tokenize equity, cap table data is recorded on a public blockchain. This data is immutable and cannot be deleted. Only tokenize information you intend to make public.
Self-hosting
For maximum control, self-host aeqi on your own infrastructure. Source is available. Your data never leaves your network.
Reporting vulnerabilities
If you discover a security vulnerability, please report it to security@aeqi.ai. We take all reports seriously and will respond within 48 hours.