Epic logo
Epic AI
Core
Back to Core

Security

Core Security Overview

This overview explains the baseline controls Epic AI Core uses to protect customer workspaces during beta and paid pilots.

Last updated: June 26, 2026

Workspace isolation

Core stores workspace records with account identifiers and requires an active authenticated session before loading chats, projects, files, data tools, apps, media, analytics, billing, or admin settings. Shared objects are available only according to their workspace visibility, user permissions, and client-link grants.

Authentication and launch

Normal production access is launched through Epic Hub SSO. Core verifies launch tokens with Epic Hub, consumes each token once, maps the Epic Hub user and account to local records, then starts a secure local session.

Provider keys and secrets

AI provider keys, billing secrets, webhook secrets, and integration tokens are managed as server-side configuration or encrypted server-side records. Core does not display stored secret values back to users and redacts provider keys, tokens, signed URLs, and sensitive payloads from logs and error messages.

Commerce and client data boundaries

Commerce queries, dashboards, exports, hosted apps, async jobs, caches, logs, support tools, backup handling, and restore handling are designed around account and workspace scope. Client links are grant-limited and should not be treated as general workspace access.

Audit and operations

Admin, invite, provider, usage-limit, support retry, email delivery, commerce dashboard, provider failure, and relevant workflow events are recorded as audit events so the team can investigate operational and access issues.

Incident contact

Report suspected unauthorized access, data exposure, billing problems, or provider abuse to support@epicglobalinc.com. Include the workspace name, approximate time, affected feature, and any safe screenshots.