Security

Security and accountability, built in

EOCC is engineered for the trust requirements of government, healthcare, and critical infrastructure operations.

Role-Based Access Control

Four built-in roles with least-privilege defaults. Permissions are enforced server-side on every request.

Audit Logging

Immutable record of every privileged action — actor, entity, and timestamp — scoped per organization.

Encryption & Secrets

Encrypted credentials, hashed passwords (bcrypt), and signed, expiring access tokens.

Multi-Tenant Isolation

Every record belongs to an organization; queries are automatically scoped to your tenant.

SSO & SCIM

SAML single sign-on and SCIM user provisioning available on Enterprise plans.

Flexible Deployment

Run in your own cloud, VPC, or fully air-gapped via Docker Compose.

API-First

A documented OpenAPI surface for every capability, enabling secure automation and integration.

Data Processing Agreement

DPA and security review available for enterprise and public-sector procurement.

Privacy

We collect only what is required to operate your workspace. Operational data you import or connect remains yours and is isolated to your organization. Demo workspaces contain only synthetic data generated for evaluation. We never sell customer data, and you can request export or deletion of your organization's data at any time.

Terms of Service

Use of the platform is governed by your subscription agreement. Enterprise customers receive a negotiated MSA, DPA, and uptime SLA. This demonstration deployment is provided for evaluation purposes and uses synthetic operational data.