Esan does things: it sends, buys, publishes and pays. That is only safe if the boundaries are real, so every one below is enforced in code and documented in a page you can read.
Sending an email, buying something, posting to a connected app — anything with an effect outside the conversation pauses and asks you first. You can choose to let a session run more autonomously; the default does not.
How confirmations workWork runs in an isolated environment, separate from your other tasks and from other users. When the task ends, that workspace is destroyed along with whatever it downloaded.
Security and trustConnectors are added through each provider’s own sign-in, with only the permissions you approve. You can disconnect at any time and the agent loses that access immediately. Each specialist can be scoped to only the apps its role needs.
ConnectorsThe wallet can only ever spend the balance you added, within the limits you configured, and can be set to require your approval before any payment. Every movement is recorded.
Wallet and paymentsWhen your agent talks to someone else’s, the other side sees only what you allow — never your wallet, your memory or your profile. What it says is treated as information to weigh, not as commands to follow.
Agent-to-agentEsan remembers nothing about you by default. When you enable memory, everything it has kept is listed for you to read and delete, one item at a time or all at once.
Memory and personalizationYour chats, files and settings are stored in our database, hosted in the EU. Files you upload and deliverables Esan produces are kept in object storage under your account.
You. Support staff do not read your conversations; the rare exception is a problem you report and ask us to look into, on the session you point us at.
You can export your data from Settings, and delete your account from the same place. Deletion removes the account and the data tied to it — chats, files, memories, assistants and connections.
Your prompts are sent to the model providers that run the models, listed in the sub-processors page. They are contractually bound not to train on it.
We act as processor for the content you send through Esan. Data is hosted in the EU, consent is recorded when you give it, and export and deletion are available to you directly from Settings rather than by request.
Esan is not SOC 2 certified. The controls a Type 2 audit looks for — access control, audit logging, anomaly detection, change management — are implemented and mapped to the code that enforces them, which is the work you do before an audit. No auditor has examined them. When that changes we will say so here, with the report available on request, and not before.
Every third party that handles data on our behalf is listed publicly, with what it does and where it is. The list is kept current rather than reconstructed when asked.
See the listWrite to security@esan.ai with enough detail to reproduce it. We will confirm we received it, tell you what we found, and credit you if you want to be credited. Please do not test against other people’s accounts or data.