Your documents are encrypted. On the disk itself.
Everything you put into Epimonos — documents, conversations, your knowledge base — lives on a separate, encrypted volume. If a disk ever leaves our data centre, or a backup ends up somewhere it shouldn't, what's on it is unusable without your key. Unlocking is tied to your own machine: the volume won't open anywhere else.
You hold the spare key. At handover you receive a recovery key, once. We don't keep it — not in our systems, not in our backups. Lose a password and that key always gets you back in.
We'd rather be accurate than impressive.
That's true of any managed service where someone performs maintenance. So we log every administrator login, with a stated reason, visible in your control panel. And if you want us technically locked out as well, Sealed mode does exactly that: after every restart your environment stays closed until someone at your firm opens it.
Two modes. Yours to pick, at onboarding or later.
Managed mode
Encrypted, and always immediately available. The right choice for nearly everyone.
Sealed mode
After every restart your environment opens only once someone at your firm signs in. One screen, ten seconds. For those who weigh professional privilege above convenience.
Encryption uses LUKS2 (AES-256-XTS), the Linux standard for disk encryption. Backups are taken at block level and cannot be read without your key. If you lose every key, your data is permanently unreachable — including to us. That is exactly how it should work.
Have more questions about how this works day to day? See our FAQ.