
Security
Core Security Overview
This overview explains the baseline controls Epic AI Core uses to protect customer workspaces during beta and paid pilots.
Last updated: June 26, 2026
Workspace isolation
Core stores workspace records with account identifiers and requires an active authenticated session before loading chats, projects, files, data tools, apps, media, analytics, billing, or admin settings. Shared objects are available only according to their workspace visibility, user permissions, and client-link grants.
Authentication and launch
Normal production access is launched through Epic Hub SSO. Core verifies launch tokens with Epic Hub, consumes each token once, maps the Epic Hub user and account to local records, then starts a secure local session.
Provider keys and secrets
AI provider keys, billing secrets, webhook secrets, and integration tokens are managed as server-side configuration or encrypted server-side records. Core does not display stored secret values back to users and redacts provider keys, tokens, signed URLs, and sensitive payloads from logs and error messages.
Commerce and client data boundaries
Commerce queries, dashboards, exports, hosted apps, async jobs, caches, logs, support tools, backup handling, and restore handling are designed around account and workspace scope. Client links are grant-limited and should not be treated as general workspace access.
Audit and operations
Admin, invite, provider, usage-limit, support retry, email delivery, commerce dashboard, provider failure, and relevant workflow events are recorded as audit events so the team can investigate operational and access issues.
Incident contact
Report suspected unauthorized access, data exposure, billing problems, or provider abuse to support@epicglobalinc.com. Include the workspace name, approximate time, affected feature, and any safe screenshots.