KRUTRIM EKAMAgent-identity control plane

Security & key custody

How Ekam protects the key that signs your agents' identities · operated by Krutrim SI Designs Private Limited (a Krutrim group company)

Ekam issues the identity tokens your agents authenticate with. The key that signs those tokens is the single most sensitive secret we hold — so we treat it accordingly.

Hardware-rooted key custody

What this means for you. Compromising our datastore yields no usable signing key; there is no static credential to steal; and you can independently verify both the custody posture and every token we issue.

Verify it yourself

Compliance posture

This design keeps Ekam outside the PCI-DSS audit boundary while inheriting HSM-rooted trust, mirroring the pattern used by our IAM and SSH key-management services. Personal data is stored and processed on Krutrim Cloud, in India, with cross-region disaster recovery (see DPDP and Privacy).

Scope, stated plainly. Signing is performed in application memory, not inside the HSM. Full "the key never touches a host under any circumstance" assurance is covered by third-party audit on our roadmap — we don't claim it here.

Security questions or a vendor assessment? Contact security@olakrutrim.com.