Compliance context
Customer operation gives you control of the deployment. It does not turn software into a certification.
Last updated 4th September 2026.
The boundary comes first
Ekso is software your organization installs and operates. You select the infrastructure, database, object storage, identity provider, network exposure, integrations, and optional AI endpoints. Ekso Inc. does not host the operational instance or receive its content as part of normal operation.
That architecture can reduce the number of external data paths your team must review. It does not remove the Ekso deployment from the system you assess, and it does not make the deployment compliant by construction.
What Ekso does not claim
- Ekso is not FedRAMP authorized.
- Ekso is not a CMMC-certified product.
- Ekso Inc. does not currently publish a SOC 2 Type II report or ISO 27001 certificate.
- Installing Ekso does not automatically satisfy ITAR, HIPAA, GDPR, PCI DSS, DORA, FISMA, or an agency authorization.
- We do not currently make a categorical air-gap or zero-egress promise. Validate the release and update process against your network requirements.
Defense and government environments
If an Ekso deployment stores or processes Federal Contract Information, Controlled Unclassified Information, or other government data, it becomes part of the customer’s scoped system. The customer and its assessors remain responsible for applying the relevant DFARS, NIST SP 800-171, CMMC, FISMA, agency, contractual, and authorization requirements.
A customer-operated deployment may be useful when a team needs to keep operational data inside an existing enclave. The customer must still configure access, encryption, logging, backups, incident response, change control, and evidence collection for that environment.
Export-controlled and aerospace work
The customer determines whether program information is subject to ITAR, EAR, contractual restrictions, or an aerospace quality system. Hosting location is only one part of that analysis. Identity, nationality, support access, exports, attachments, integrations, and AI endpoints can all affect the permitted data path.
Privacy and health data
For GDPR, UK GDPR, HIPAA, and similar regimes, legal roles depend on the deployment, contracts, support arrangement, and actual handling of data. Customer operation can keep operational content out of Ekso Inc.’s normal data path, but it does not automatically eliminate every DPA, BAA, transfer assessment, or vendor-risk obligation. Confirm the required agreements with your privacy or legal team.
AI and external integrations
Ekso uses customer-supplied credentials for supported AI providers. Prompts and related content travel from the customer environment to the endpoint the customer configures. Treat that provider and data flow as part of your system boundary, retention policy, and vendor assessment. The same principle applies to identity, email, storage, webhooks, and other connected services.
Current product controls
- Customer-selected SQL database and object storage.
- Microsoft Entra ID single sign-on.
- Role-based permissions across operational work.
- Customer-supplied AI credentials and endpoints.
- Documented migrations from Jira, Linear, Azure DevOps, Zendesk, and Countersoft Gemini.
What remains your responsibility
- System scoping, risk assessment, and authorization.
- Network architecture and approved inbound/outbound paths.
- Encryption, keys, secrets, backups, and disaster recovery.
- User provisioning, access reviews, and deprovisioning.
- Logging, retention, monitoring, and incident response.
- Integration and AI-provider due diligence.
- Operating procedures, training, and assessment evidence.
Procurement and evidence requests
For architecture questions, deployment reviews, vendor questionnaires, or evidence requests, email sales@ekso.app. We will state what is available, what is planned, and what remains the customer’s responsibility.