Security Policy
Last Updated:
At Echonic, securing your data and ensuring the reliability of our AI platform is our top priority. We implement industry-standard security measures to protect your infrastructure and personal data.
1. Data Encryption
All data transmitted between your applications and our API endpoints is encrypted in transit using TLS 1.3. Data at rest, including chat logs and user profiles, is encrypted using AES-256 encryption.
2. Compliance & Privacy (PDPA)
Our security architecture is designed to comply with global privacy frameworks, including the Thai Personal Data Protection Act (PDPA). We ensure strict access controls, data minimization, and secure audit trails for all data processing activities.
3. Infrastructure Security
- Cloud Hosting: We partner with leading cloud providers (AWS/GCP) adhering to SOC 2 and ISO 27001 standards.
- Vulnerability Scanning: We conduct regular automated vulnerability scans and annual third-party penetration tests.
- DDoS Protection: Our edge networks are equipped with advanced DDoS mitigation to ensure high availability.
4. Reporting a Vulnerability
If you believe you have discovered a security vulnerability in our platform, please report it immediately to our security team at: security@echonic.ai. We ask that you do not disclose the vulnerability publicly until we have had a chance to address it.