Last updated: August 21, 2026 · Epic One by Hearken.ai, a Good Time Andys LLC brand
Epic One works inside your ERP on your behalf, so we designed it around a
simple principle: your company's data lives on your company's own
server, and nowhere else. This page describes, concretely, how that
works. Everything here describes the system as built — not aspirations.
One dedicated server per customer
Every Epic One customer runs on their own dedicated cloud server
with its own database, its own encryption keys, and its own web address
(yourcompany.epicone.hearken.ai). There is no shared database, no
shared application instance, and no multi-tenant data store. Another
customer's Epic One cannot reach yours — they are separate machines.
Isolated compute and storage: your conversations, documents, learned procedures, and ERP activity records exist only on your server.
Per-company encryption keys: the key that encrypts your stored ERP and portal credentials is generated on your server when it is created and is stored only there.
Network hardening: each server exposes only its public web ports over TLS (HTTPS). Administrative access is restricted at the firewall to our operations server — not open to the internet.
Isolated backups: nightly backups are written off-server to isolated, per-customer storage paths with at-rest encryption, so your service can be restored after a failure.
Passwords stay home: your team's passwords exist only as salted one-way hashes in your server's own database — never in plaintext, and never copied to any central system.
The hub-and-spoke design: the central hub only routes
sign-ins to the right server and watches server health. Conversations, documents, credentials,
and ERP data live on each customer's own server — they never pass through the hub, and there
are no connections between customer servers. Code updates arrive from our operations server —
never through the hub — in a staged, version-verified rollout that runs on a data-free canary
server first, then reaches every customer server directly.
Sign-in security
Your team signs in with phone, company, and password. Passwords are verified only on your own server — our central sign-in service routes you there and never stores or checks passwords itself.
Login sessions are cryptographically bound to your company's server; a session token from one company is useless anywhere else.
Repeated failed sign-ins lock the account temporarily, at both the central service and your server.
Passwords & where your data lives
One-way hashing, never plaintext: passwords are stored only as salted one-way hashes using scrypt, a modern memory-hard algorithm. A password can be checked but never read back — not by an attacker who obtains the database, and not by us.
Hashes never leave your server: the central sign-in directory used for routing holds only name, phone, company, and admin status. No password — not even the hash — is ever copied off your server.
Temporary passwords are single-purpose: when an account is created for you during onboarding, its temporary password is randomly generated, and the account is required to choose its own new password at first sign-in.
Masked entry everywhere: password fields are masked in every interface, including when a password is entered in the chat.
All of your company's data lives in one database on your own
server: your users, conversation history, documents, learned company
knowledge, and the complete ERP audit trail. Stored ERP and portal credentials
are additionally encrypted inside that database with the key that is generated
on — and never leaves — your server. Nightly backups of that database are
per-customer and encrypted, as described above. We publish what the database
protects rather than its internal layout, deliberately.
ERP safety: the write gate and the audit trail
Reading data is one thing — changing your ERP is another. Epic One treats
every ERP change as privileged:
Approval before every write: when Epic One is about to create or change ERP records, it first shows a preview of exactly what it will do, and waits for approval from a person your company has authorized. This gate is on by default.
Complete audit trail: every ERP action — reads and writes, approved and attempted — is recorded in an audit log on your server: who asked, what was done, and the result.
Rehearsed before production: new automated procedures are learned and rehearsed against your test/sandbox ERP environment, and first production runs are supervised live by a named person on your team.
AI processing
Epic One's core intelligence runs on an enterprise AI service through its commercial API. Under those commercial terms, your data is not used to train AI models.
Optional features — image, video and spoken-voice generation — use additional vetted providers, and only when your team uses those features.
Only the context needed to answer the current request is sent for processing; your credentials are never included.
What our operations team can and cannot see
We manage the fleet of customer servers, and we're precise about what that
involves:
Our fleet operations sees
It does not see
Server health (up/down, memory, disk)
Your conversations or chat history
Usage totals for billing (call counts, token counts, cost)
Your documents or generated files
Sign-in directory (name, phone, company — for routing)
Your ERP or portal credentials (encrypted with your server's key)
Our engineers can access customer servers for maintenance, deployment, and
support of your own service. Your data is never accessible to any other
customer, never sold, and never used for advertising.
Staged, verified updates: code updates reach your server only
after running on a staging server that contains no customer data, and each
server's running version is verified during the rollout before the next
server is touched.
One admin path: administrative access to your server comes
only from our operations server, allowed through your server's firewall —
there is no other administrative path from the internet.
Your data is yours — including on the way out
Your company owns its data: users, conversation history, learned procedures, company knowledge, and the full ERP audit trail.
At termination, we provide a complete export of that data using the same migration tooling we use operationally, then delete your server. Retained backups age out on a stated schedule per your agreement.
Service providers we rely on
Category
Purpose
Cloud hosting
Dedicated servers for each customer's instance, plus encrypted backups and file storage
AI processing
The core assistant (commercial API; no training on your data)
Optional AI media & voice
Image, video and spoken-voice features, used only when your team uses them
Messaging
SMS conversations with your team
Email delivery
Notifications sent from our domain, with a backup delivery service
Web reading
Reading public web pages your team asks about
Billing & payments
Invoicing and card payments (card data is held by the payment processor, not by us)
Certificates
TLS certificates that encrypt every connection
Services you connect
Only if your company connects its own account, for example cloud storage or social channels
Customers receive the full named list of providers with their agreement, and
we notify them before adding a provider that receives their data.
Questions?
We're happy to walk your IT team through any of this in detail —
info@hearken.ai.