ErmisAI
PricingLyraPartnersAboutContact
Security

What we have. Not what we hope to have.

Role-scoped access. Sensitive-topic review built into the workflow, not bolted on. Source context, confidence, conflicts, usage metering, and vendor disclosures stay visible where the product supports them. What we don't claim yet, we don't claim.

Managed infrastructure

Security-critical layers run on managed services rather than custom infrastructure. Each provider is responsible for their own layer. Specific provider names and DPA terms are available before contract.

Authentication

Authentication and session management

Authentication, sessions, and organisation membership are delegated to a managed identity provider. ErmisAI does not store or manage raw session credentials.

Billing

Billing and subscription lifecycle

Payment processing, subscription state, and checkout flows run through a managed billing provider. Card data never touches ErmisAI servers.

Database & storage

Primary database & object storage

Application state, tenant data, and editorial records live in a managed Postgres cluster in the EU (Helsinki, Finland); uploaded media and payload archives live in the hosting platform's object store, with archives held under a private ACL. Backups, failover, and encryption at rest are handled by the providers.

Cache and rate limiting

Rate limiting and transient state

In-memory state for rate limiting, feed processing locks, and short-lived workflow flags. No persistent sensitive data stored here.

Compute, hosting & edge

Compute, hosting, edge delivery & object storage

Application compute, routing, edge CDN, and object storage run on a managed hosting platform (compute in the EU, Stockholm, plus global edge). Network isolation, DDoS mitigation, and TLS termination are platform defaults.

Conflict detection

When sources disagree, the draft says so

NordwireUnanimous

The board voted unanimously to hold rates, citing easing core inflation.

Baltic PostSplit board

The decision to hold rates came from a split board, people familiar said.

Conflict
Story draft
ConflictProvenance attached

Outlets diverge on the vote breakdown — the discrepancy is carried in the draft, attributed to both sources.

▸Reading two reports on the same decision
Disagreements between sources are flagged and attributed, never averaged away.
Product controls

Controls implemented at the application layer, visible in the current codebase.

01

Role-gated product areas

Admin routes and tenant newsroom routes are separated at the middleware level. Platform-side roles for operations are distinct from tenant-side editorial roles. Access is enforced server-side on each request.

02

Webhook signature verification

Billing and identity webhook events are verified against HMAC signatures from their respective providers before processing. Replayed or tampered payloads are rejected. Idempotency keys prevent duplicate processing of the same event.

03

API key hashing

Tenant integration keys are stored as hashed values with truncated masked prefixes for display. The full key is shown only once at creation time and cannot be retrieved from the platform after that.

04

Network checks for webhook targets

Outbound webhook endpoints submitted by tenants are validated against reserved and non-public address ranges before use. This blocks SSRF attacks targeting internal network addresses via the webhook delivery system.

05

Operational records

Billing and identity webhook payloads are archived for audit and incident investigation. These records support troubleshooting without relying solely on external provider logs.

What we do not claim

Security pages often overstate. These are the things this page does not assert.

01

No certification unless published.

ErmisAI does not hold SOC 2, ISO 27001, or equivalent certifications at this stage. If any are obtained they will be published explicitly. A security page is not a certification.

02

No public bug bounty.

There is no active public bug bounty programme. Security researchers should report findings to the security contact. Reports are reviewed; rewards are not promised.

03

No uptime SLA unless contracted.

Free, Plus, and Pro plans carry no uptime guarantee. Enterprise contracts may define SLAs - consult the specific agreement.

04

No prevention of AI editorial errors.

The product generates AI articles. These may contain factual errors, misattributions, or incomplete coverage. Editorial review before publication is a design assumption, not an optional step.

05

No substitute for publisher rights review.

Security controls do not address content licensing, attribution rights, or syndication terms. Those are separate legal and commercial matters.

Found a security issue?

Report via the security channel. Include the affected path, reproduction steps, and your estimated impact. Reports are reviewed - there is no public bounty programme.

security@ermisai.comAll contact channels →
ErmisAI

The AI newsroom for modern publishers. Source intake, same-event clustering, story synthesis, editorial review, and delivery into supported publishing surfaces.

XLinkedIn

Product

  • Lyra
  • Pricing
  • Partners
  • Security
  • Contact

Company

  • About
  • Careers

Legal

  • Terms
  • Privacy
  • Cookies
  • GDPR
  • Sub-processors
  • AI policy

© 2026 ErmisAI. All rights reserved.

Your multilingual AI newsroom.