Trust & Security

Your data stays with your team. You connect the AI you already use.

For IT and procurement reviewers

For business owners

Start on Home, Pricing, or Contact

This page is the trust and security overview for IT and procurement reviewers. For apps, pilot pricing, and a live demo, start on Home, Pricing, or book a 30-minute demo.

How the workspace works

Three roles: one isolated company workspace per business. Everyday common utility tools plus one industry pack; depth grows by plan tier. Browse apps by industry.

Platform operator

  • Creates client workspaces from the operations console
  • Sets industry vertical and plan (Starter / Standard / Elite / Enterprise)
  • Controls which catalog apps are Live vs coming soon
  • Provisions company admins and team sign-ins

Client admin (setup)

  • One-time AI account setup: connect supported providers under your AI provider account (Bring Your Own Subscription: your API key, your provider bill), including OpenAI, Together, Groq, xAI (Grok), and others; full list in admin setup
  • Encrypted credentials stored per company workspace; never logged
  • No day-to-day workspace or industry apps on this login

Team members (daily use)

  • Run structured AI apps: forms and tuned prompts, not open chat
  • Plan tier controls user count and which apps unlock
  • Upload, draft, summarize, and extract inside company workspace boundaries

Customer questions, answered

Your Data & Security

How EZ4YouTech.com stores workspace data, retention and purge rules, and what your team controls.

What We Store

  • Tenant workspace data in MongoDB Atlas and Azure Blob
  • Files, app runs, email drafts, reminder CSV imports, plus accounts and settings
  • Paths stay scoped to your company workspace
  • We do not sell your data. We do not use workspace content to train public AI models; when you connect your AI provider account, inference and provider data-use terms apply to that provider

How We Defend It

  • HTTPS-only traffic, Key Vault secrets, encrypted provider credentials, and tenant isolation on every API call
  • Passwords are hashed; provider API keys are never logged or exposed in the browser
  • Login rate limits, security headers, and WAF/rate limiting on public surfaces
  • Connect your AI provider account: inference runs on your provider terms

If Something Goes Wrong

  • No system is 100% safe. We follow our incident runbook: contain (rotate keys, preserve logs), fix, and redeploy
  • Notify affected customers without undue delay; Enterprise DPA target: within 72 hours when personal data is involved
  • We explain what happened, what data types may be affected, and what we have done
  • Cyber insurance and counsel as needed

What You Can Do

  • Agents clear their own files, analyses, app runs, email import history, and reminder CSV history
  • Company admins can purge org-wide workspace data from Company setup; user accounts, billing, and OAuth connections stay in place
  • Use strong passwords, limit admin seats, and review uploads before you trust the cloud with regulated records

Retention & Purge Policy

  • Workspace history uses plan-tier hybrid retention (keep while among recent items or within your plan day window). Starter Free: up to 25 runs or 21 days per tool. Standard+: up to 50–100 runs or 90–180 days (see pricing)
  • Archived email batches are removed after 90 days by scheduled ops jobs
  • Deactivated workspaces are retained per our privacy policy, then purged with advance notice by email
  • Policy and quote compare flows are session-only; they do not keep a long-term file vault in workspace storage

Certifications & Standards

  • Built for client-facing and regulated work with an enterprise-ready architecture
  • We do not claim SOC 2, ISO 27001, or HIPAA certification on the standard plan unless separately agreed in an Enterprise contract

Deeper review: Architecture & security guide · Security FAQ · Privacy policy

Security at a glance

Built for client-facing and regulated work. See Your Data & Security for retention, purge, and certification details.

  • your AI provider account (Bring Your Own Subscription): your API keys, encrypted per company; never logged; billed by your provider
  • Tenant isolation: tenant_id on every JWT-backed request and storage path
  • Role separation: admins configure keys; users run apps without handling secrets
  • No data resale: subscription revenue only; prompts not sold for ads or model training

Core security controls

How we protect tenant data and credentials in the live application.

Authentication & access

  • JWT with tenant_id, plan, and role on every API call
  • bcrypt password hashing; login rate limiting per IP
  • RBAC: platform operator, partner, company admin, user
  • Plan gating: app catalog and agent seats enforced server-side

provider account & data handling

  • Fernet-encrypted provider keys in MongoDB Atlas
  • Keys decrypted only for outbound provider requests
  • Uploads and run history under tenant_id/ storage paths
  • Production security headers (HSTS, X-Frame-Options, Referrer-Policy)

Deeper diagrams: Architecture & security guide · Security FAQ

Technology stack & operations

For IT and security reviewers: USA production posture (May 2026).

  • Azure production stack: Container Apps + Key Vault + Blob Storage
  • MongoDB Atlas: tenants, users, usage, and encrypted subscription credentials
  • provider account routing: tenant-owned keys to supported providers (try-order when multiple are configured)
  • Tenant isolation: enforced by tenant_id across API and storage paths

Production stack

LayerTechnologyRole
EdgeHTTPS, CDNTLS for marketing site and platform hostname
ApplicationFastAPI + Next.jsREST API and agent/admin workspace UI
ComputeAzure Container AppsManaged runtime, tagged releases
SecretsAzure Key VaultJWT key, encryption key, Mongo URI, not in git
DatabaseMongoDB Atlas (M10)Tenants, users, encrypted subscription credentials, usage
StorageAzure BlobTenant-scoped documents and artifacts
AIOpenAI, Together, Groq, xAI (Grok), DeepSeek, Mistral, Fireworks, OpenRouter, Azure OpenAICustomer keys; billed on your provider account

Security & data protection

AreaPractice
Data in transitTLS 1.2+ end-to-end
Secrets at restFernet encryption for AI subscription credentials
Tenant isolationAPI checks + tenant_id/ blob paths
LoggingNo keys, passwords, or raw prompts in app logs
OpsAzure Monitor; Atlas backups; blob soft-delete

Your responsibilities

  • Protect admin credentials and rotate AI subscription credentials per your policy
  • Set training / opt-out in your AI provider console
  • Human-review client-facing outputs in regulated industries

Supported AI providers

Connect the AI services you already use. You pay providers directly; EZ4YouTech.com does not markup tokens.

Your company admin configures credentials and try-order in the Secure AI Platform setup tab (comparison table with illustrative list prices). Router-ready providers:

  • OpenAI, Together AI, Groq, Fireworks AI, DeepSeek, Mistral AI
  • xAI (Grok): different vendor from Groq (groq.com)
  • OpenRouter, Azure OpenAI

Anthropic, Google Gemini, and AWS Bedrock appear in the setup comparison; native API routing ships in a later release. Legacy Anyscale keys are not offered for new setups.

Watch · ~3 min

Monday Morning on the AI Platform

From blank chat tabs to a guided workspace. Scenario A Connect AI, Scenario B client reminders, Scenario C bulk email. Approve before send.

  • Monday 8am
  • Scenario A · Connect AI
  • Scenario B · Reminders
  • Scenario C · Bulk Email
AI Platform explainer · EZ4YouTech.com

Workspace tour

Screenshots of the live product for reviewers who need context after the security sections above.

Open live workspace

EZ4YouTech.com platform dashboard showing workspaces, AI routing, and team analytics

Workspace

Catalog apps by plan and industry

AI router

Route to your connected AI providers

Credentials

Encrypted keys: never logged

Team & plans

Roles, users, and access

Ready to see it on your stack?

Start with a pilot: connect your AI accounts, run one workflow, then scale users and plan tier.

Positioning and cost comparison, Home · FAQ