Skip to content

EthenEthenEthen

Legal & Trust Center

Enterprise Security

Effective date
Not yet in effect
Last updated
Version
1.0 · Pending finalization

Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.

This page is for security, privacy, procurement and legal teams evaluating Ethen for their organization. It explains how Ethen is built: its architecture, identity and administration, data boundaries, the AI model providers involved, connected apps, local and cloud execution, and what documentation and contractual terms are available today. It is a factual guide, not a certification report or a substitute for a contract. Read it alongside the Privacy Policy and the Subprocessors list.

On this page
  1. What Ethen is today
  2. Architecture
  3. Identity and administration
  4. Data boundaries
  5. AI model providers
  6. Connected apps and actions
  7. Local and cloud execution
  8. Security controls
  9. Compliance
  10. Documentation and contracting
  11. Questions from reviewers
  12. Related policies
  13. Contact
  14. Version history

What Ethen is today

ProductStatusWhat organizations should know
Ethen ChatAvailable, with beta usage limitsAI conversation, artifacts, web research and voice. Individual accounts only.
Ethen StudioEarly accessImage, video and audio generation through third-party media providers. Individual accounts only.
Ethen PlatformWaitlistOrganization console, connected apps and automation are not yet available.
Connected appsNot yet availableGmail, Google Drive and Google Calendar are planned first.
Ethen CodeNot yet availableDesktop app, local runtime and cloud worker for coding tasks.
Bring your own keyNot yet availableSee BYOK Data Handling.
Organization administration and single sign-onNot yet availableNo Organization accounts, admin console, SAML/SCIM or domain controls today.

Ethen today is used through individual accounts. If your organization adopts it now, each person signs up individually, and Upcube cannot give your organization administrative control over those accounts or their content.

Architecture

LayerProviderNotes
Web apps (Chat, Studio, Platform)VercelServer code runs in a U.S. region. Strict Content Security Policy, HTTPS with HSTS.
Database, file storage, secrets vaultSupabase on AWSOne production project in the U.S. (us-west-2). Row-level security on conversation data. Private file storage.
IdentityClerkEmail and password, or Google sign-in. One account across Ethen apps.
Website and DNSCloudflareupcube.ai runs on Cloudflare's network.
Caching and coordinationUpstashShort-lived coordination data for Ethen Chat.
AI modelsMeta (default Chat model), OpenAI, Anthropic, Google, DeepSeek (selectable), through direct APIs and the Vercel AI GatewayRequests use Upcube's provider accounts.
ResearchTavily, FirecrawlUsed when web search or deep research is turned on.
Media generationfal, OpenAIUsed by Ethen Studio.

Staging and production use separate database projects. The full provider list, with data categories, is on the Subprocessors page.

Identity and administration

  • Sign-in is handled by Clerk with email and password or Google. Single sign-on through your own identity provider, SCIM provisioning and enforced multi-factor authentication are not available today.
  • Users can review and end their own sessions.
  • There are no Organization roles, administrators or audit views today. Upcube's own administrative access is restricted to named staff accounts.

Data boundaries

  • Isolation between users. Conversation data is protected by row-level security that limits each account to its own records. Files are checked against project membership. Privileged server access is scoped in code to the requesting account or project.
  • Where data is stored. Ethen's database and file storage are in the United States. Data residency in other regions is not available.
  • What leaves Ethen. Prompts and conversation context go to the AI model that answers them. Search queries go to the search provider. Studio prompts and references go to the media provider. Voice audio goes from the user's browser to the realtime voice provider without passing through Upcube's servers. The Privacy Policy maps each path.
  • Retention. Conversations are kept until deleted, and deletion is immediate in Ethen's database. Several categories do not yet have fixed periods. See the Data Retention Policy, which states each one plainly.

AI model providers

Ethen routes each request to one model. By default, Ethen Chat's conversational experience uses Meta's Muse model through Meta's API. Faster and deeper modes, and models users select, use other providers through the Vercel AI Gateway. Requests use Upcube's accounts with these providers, so their terms with Upcube apply to retention and data use.

Ethen does not currently offer organization-level controls to restrict which providers members can use, zero-data-retention routing, or your own provider agreements through BYOK. Organizations with requirements in these areas should treat them as unmet today.

Upcube's position on using customer content for model training is stated in the Privacy Policy.

Connected apps and actions

Connected apps are not yet available. As built, connections use OAuth with incremental permissions. Credentials are stored in an encrypted vault and used only server-side. Actions follow approval rules: reads run without approval, drafts and edits ask, and sends always ask. Users can grant time-limited standing approvals for lower-risk actions. There is no unattended automation. Connected Apps & Integrations lists the exact permissions and actions.

Local and cloud execution

Everything in Ethen today runs in Upcube's cloud environment and its providers. Ethen Code, when released, will add a desktop app and a local runtime that runs commands on the user's computer, plus a cloud worker that runs tasks in isolated environments. Local execution will not make Ethen fully offline. Ethen Code & Repository Data describes the planned boundaries.

Security controls

Ethen's current controls authenticate requests to personal data, isolate accounts, keep secrets on the server, check content before accepting it, and stop affected features when required safeguards are missing. Security is shared: Upcube operates these controls, providers secure their infrastructure, and users protect their accounts and review the content and actions they submit.

  • Identity and access. Clerk manages passwords and Google sign-in; Ethen does not store passwords. Sign-in pages support Cloudflare Turnstile bot challenges. Users can inspect and end sessions. Database row-level security isolates conversations, messages and artifacts; file and project access checks membership. Privileged database operations bypass row-level security but are restricted to server code and scoped to the requesting account or project. Staff administration is restricted to named accounts.
  • Secrets and environments. Provider credentials stay in encrypted hosting secrets, never in the browser. Required production configuration is checked at startup. Staging and production use separate database projects; production rejects mock providers, sample data and development sign-in shortcuts. Connected-app credentials, when available, use a managed encrypted vault accessible only through restricted server functions and are not sent to models.
  • Transport and browser protections. App domains use HTTPS with HSTS and a strict Content Security Policy that limits scripts and destinations and prevents framing by other sites. Origin checks reject unexpected cross-site requests. Database and file storage rely on Supabase and AWS's managed storage protections..
  • Model requests. Server code makes encrypted provider calls using Upcube credentials and restricts the available models. Realtime voice is an exception: the browser connects directly with a single-use credential that expires after ten minutes. Model output alone cannot execute connected-app actions. Hidden instructions in external content can still mislead a model; users should review outputs and proposed actions. See AI Use Policy.
  • Admission and usage limits. Chat attachments currently fail closed because the required scanner is not configured. Upload admission checks file types, size and a required scanner verdict. Chat has rate and usage limits; Studio checks generation requests before sending them to media providers.
  • Incident containment. Operators can disable Studio, stop connected-app actions, pause action resumption, freeze connection changes and disable Vercel AI Gateway routing without a code change.

Monitoring and recovery limits

Hosting and identity providers retain request and sign-in logs under their own settings. Ethen records significant account actions such as exports and account deletion. There is no dedicated security-monitoring system or tamper-evident audit log. The database provider keeps operational recovery copies, but Upcube has not enabled point-in-time recovery or separate long-term backups. Recent data could be lost in a serious failure; no recovery-time or recovery-point commitment is offered. No independent penetration test report is available.

How and when Upcube will notify affected users and customers of security incidents will be stated here before this statement takes effect, in addition to any notice the law requires.

Reporting vulnerabilities and protecting your account

A dedicated channel and rules for reporting security vulnerabilities, including any safe-harbor commitment, will be published here before this statement takes effect.

Until a dedicated channel is published, use the contact options in the Legal & Trust Center for security reports. Do not access, modify or delete other users' data or degrade the Services. Stop and report once a problem is found. See Acceptable Use Policy for the rules on security testing.

Use a unique password or a Google account with two-step verification, end unused sessions and sign out on shared devices. Chat caches conversation history in the browser. Do not submit passwords, private keys or production secrets in prompts. Review consequential actions before approval and, when connected apps become available, revoke unused connections and standing approvals.

Compliance

Ethen does not hold SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP or other certifications, and does not claim compliance with any regulatory framework. Approvals and records in Ethen may help your own governance work, but they are not a compliance archive. Your organization remains responsible for deciding whether Ethen meets your legal, regulatory and contractual requirements. Do not submit regulated data, such as protected health information or payment card data, to Ethen.

Documentation and contracting

ItemStatus
Terms of ServiceTerms of Service
Privacy PolicyPrivacy Policy
Subprocessor listSubprocessors
Data processing addendumData Processing Addendum
Security questionnaire responsesNot yet available as a standard package
Organization agreement or order formSee below

Upcube has not yet published terms for organizational agreements. How organizations can request a contract, a security questionnaire or other review materials will be stated here before this page takes effect.

Questions from reviewers

Send security and procurement questions through the contact options in the Legal & Trust Center. Answers given in a review are subject to any written agreement between your organization and Upcube.

Contact

Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.

Version history

VersionDateStatusSummary of changes
1.0October 5, 2026Not yet in effectRewritten as a factual reviewer's guide.
0.9September 2026SupersededEarlier public-preview text. Archived.