Trust center · updated 2026-07-29
Controls a buyer can verify before enforcement.
Security architecture
Every stateful query is scoped to an organization. Sessions, API keys, and SCIM tokens are one-way hashed. Published policies, authorization decisions, approval outcomes, and organization audit events retain their operational history.
Enterprise identity
Enterprise identity supports OIDC Authorization Code with PKCE and JWKS validation, SAML 2.0 signed assertions, audience and domain binding, encrypted provider material, forced SSO, role mapping, and revocable SCIM provisioning.
Integrations and billing
Stripe webhooks are signature-verified and replay-protected. Composio brokers provider authorization so Endram stores workspace-scoped connection identifiers rather than raw provider credentials.
Infrastructure
The deployment supports a non-root container behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support.
Procurement documents
Security architecture · Privacy notice · Service terms
Assurance status
Endram does not claim SOC 2, ISO 27001, HIPAA, PCI, or another certification without current independent evidence.