Skip to content

Trust & security

Trust takes evidence. We’re ready to share it.

Your security review deserves clear answers. Understand how Elba protects your organization, handles data and keeps you in control of the actions it takes.

Independently assessed. Available for your review.

Our security team can provide the current assurance materials and help you assess scope, controls and fit for your organization.

SOC 2 Type II

Our current SOC 2 Type II report is available through a controlled request to the Elba security team.

ISO/IEC 27001:2022

Our current ISO/IEC 27001:2022 certificate and supporting scope information are available on request.

Built into the way Elba works

Protection with a clear operating model.

Core customer hosting

Core customer data is hosted by OVHcloud for EU environments and Neon for US environments. Processing locations can vary by feature and subprocessor; we’ll help you review the relevant data flows.

Protected access

Data is encrypted in transit, and sensitive credentials are protected at rest. Workspace boundaries and role-based permissions control access to customer information and administrative functions.

Deliberate data handling

Data processing depends on the feature. Some workflows inspect raw content or temporarily stage data; stored browser findings use classifications, cryptographic hashes and necessary metadata rather than raw prompts or file contents.

AI with defined boundaries

Customer data is not used to train or improve AI models. We can explain which AI-assisted capabilities process data, the providers involved and the controls relevant to your evaluation.

You control remediation

Connecting a source does not automatically enable every action. Remediation follows the capabilities of the integration, your configuration and the chosen workflow. Access-review revocations require a deliberate user action.

Make procurement easier

A security review with the right people in the room.

Tell us what you need to assess. We’ll bring the evidence and the context that makes it useful.

01

Share your requirements.

Send your security questionnaire, procurement requirements or questions to [email protected].

02

Review the evidence.

Request assurance reports, certificate scope and data-processing information. Identity verification or an NDA may apply.

03

Validate your deployment.

Discuss your region, applications, access requirements and proposed workflows before rollout.

A closer look

The questions that matter.

Can I download the SOC 2 report from this page?

The report is shared through a controlled request to [email protected]. Our team will confirm the appropriate materials and any access or confidentiality requirements.

Does all processing stay in my customer region?

Core database providers are listed above. Feature-specific processing, AI providers and subprocessors can involve other locations. Review the data flow for the capabilities you intend to use.

Where can I review the privacy terms?

Our Privacy Policy and Terms of Service are available in the footer. Contact the security team for additional assurance materials, contractual requirements or questions about processing.

Evaluate the product and the controls together.

See how Elba fits your environment, then go deeper on the requirements that matter to your team.