SOC 2 Type II
Our current SOC 2 Type II report is available through a controlled request to the Elba security team.
Trust & security
Your security review deserves clear answers. Understand how Elba protects your organization, handles data and keeps you in control of the actions it takes.
Our security team can provide the current assurance materials and help you assess scope, controls and fit for your organization.
Our current SOC 2 Type II report is available through a controlled request to the Elba security team.
Our current ISO/IEC 27001:2022 certificate and supporting scope information are available on request.
Built into the way Elba works
Core customer data is hosted by OVHcloud for EU environments and Neon for US environments. Processing locations can vary by feature and subprocessor; we’ll help you review the relevant data flows.
Data is encrypted in transit, and sensitive credentials are protected at rest. Workspace boundaries and role-based permissions control access to customer information and administrative functions.
Data processing depends on the feature. Some workflows inspect raw content or temporarily stage data; stored browser findings use classifications, cryptographic hashes and necessary metadata rather than raw prompts or file contents.
Customer data is not used to train or improve AI models. We can explain which AI-assisted capabilities process data, the providers involved and the controls relevant to your evaluation.
Connecting a source does not automatically enable every action. Remediation follows the capabilities of the integration, your configuration and the chosen workflow. Access-review revocations require a deliberate user action.
Make procurement easier
Tell us what you need to assess. We’ll bring the evidence and the context that makes it useful.
Send your security questionnaire, procurement requirements or questions to [email protected].
Request assurance reports, certificate scope and data-processing information. Identity verification or an NDA may apply.
Discuss your region, applications, access requirements and proposed workflows before rollout.
A closer look
The report is shared through a controlled request to [email protected]. Our team will confirm the appropriate materials and any access or confidentiality requirements.
Core database providers are listed above. Feature-specific processing, AI providers and subprocessors can involve other locations. Review the data flow for the capabilities you intend to use.
Our Privacy Policy and Terms of Service are available in the footer. Contact the security team for additional assurance materials, contractual requirements or questions about processing.
See how Elba fits your environment, then go deeper on the requirements that matter to your team.