What we can evidence today.
Security claims are easy to write and hard to check, so this page states only what we can show you now, and says plainly what is still ahead. Data protection, tenant isolation and audit logging are in place on every tier. Formal attestation is in progress. If you need a security review to move forward, we’ll do yours this week.
SOC 2 Type II
Audit program starts Q4 2026. Report shared with customers on completion.
Security questionnaires
We’ll complete yours today, no NDA required to start the conversation.
Data residency
Hosted in the United States: AWS US East, via Supabase and Vercel.
GDPR & CCPA
Data processing agreement available. Export on request; deletion within 30 days of churn.
How we protect your data.
Encryption
AES-256 at rest and TLS 1.2+ in transit, on managed Postgres in AWS US East.
Multi-Tenant Isolation
Every table is scoped to a tenant, and the API and the database both enforce it, defence in depth rather than a single check.
Access Control
Role-based access by persona with a per-role privilege system. API keys are hashed and revocable. SSO and enforced MFA are on the Q4 2026 roadmap.
Audit Logging
Every status change, every privileged action logged to an immutable audit trail with actor, timestamp, and reason.
Penetration Testing
First third-party penetration test is scheduled before general availability. We’ll share the result with customers.
AI Guardrails
MEL actions are risk-scored. High-risk writes require human confirmation. Tenant data never leaves tenant boundary.
Infrastructure
Hosted on Vercel and Supabase (AWS, US East), with managed Postgres and automated backups.
Vendor Management
Our sub-processors: Supabase (AWS), Vercel, Netlify, Stripe, SendGrid, Twilio and Anthropic. We’ll tell you before that list changes.
Vulnerability Disclosure
Email security@elevatesaas.com. We acknowledge within 24 hours, triage within 3 business days.
Request documentation.
Send us your security questionnaire and we’ll complete it, usually within a few business days. We’ll also tell you exactly where the SOC 2 program stands and when to expect the report.