Trust center · updated 2026-07-29

Controls a buyer can verify before enforcement.

Security architecture

Every stateful query is scoped to an organization. Sessions, API keys, and SCIM tokens are one-way hashed. Published policies, authorization decisions, approval outcomes, and organization audit events retain their operational history.

Enterprise identity

Enterprise identity supports OIDC Authorization Code with PKCE and JWKS validation, SAML 2.0 signed assertions, audience and domain binding, encrypted provider material, forced SSO, role mapping, and revocable SCIM provisioning.

Integrations and billing

Stripe webhooks are signature-verified and replay-protected. Composio brokers provider authorization so Endram stores workspace-scoped connection identifiers rather than raw provider credentials.

Infrastructure

The deployment supports a non-root container behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support.

Procurement documents

Security architecture · Privacy notice · Service terms

Assurance status

Endram does not claim SOC 2, ISO 27001, HIPAA, PCI, or another certification without current independent evidence.