Security & Trust

What we can evidence today.

Security claims are easy to write and hard to check, so this page states only what we can show you now, and says plainly what is still ahead. Data protection, tenant isolation and audit logging are in place on every tier. Formal attestation is in progress. If you need a security review to move forward, we’ll do yours this week.

SOC 2 Type II

Audit program starts Q4 2026. Report shared with customers on completion.

Security questionnaires

We’ll complete yours today, no NDA required to start the conversation.

Data residency

Hosted in the United States: AWS US East, via Supabase and Vercel.

GDPR & CCPA

Data processing agreement available. Export on request; deletion within 30 days of churn.

How we protect your data.

Encryption

AES-256 at rest and TLS 1.2+ in transit, on managed Postgres in AWS US East.

Multi-Tenant Isolation

Every table is scoped to a tenant, and the API and the database both enforce it, defence in depth rather than a single check.

Access Control

Role-based access by persona with a per-role privilege system. API keys are hashed and revocable. SSO and enforced MFA are on the Q4 2026 roadmap.

Audit Logging

Every status change, every privileged action logged to an immutable audit trail with actor, timestamp, and reason.

Penetration Testing

First third-party penetration test is scheduled before general availability. We’ll share the result with customers.

AI Guardrails

MEL actions are risk-scored. High-risk writes require human confirmation. Tenant data never leaves tenant boundary.

Infrastructure

Hosted on Vercel and Supabase (AWS, US East), with managed Postgres and automated backups.

Vendor Management

Our sub-processors: Supabase (AWS), Vercel, Netlify, Stripe, SendGrid, Twilio and Anthropic. We’ll tell you before that list changes.

Vulnerability Disclosure

Email security@elevatesaas.com. We acknowledge within 24 hours, triage within 3 business days.

Request documentation.

Send us your security questionnaire and we’ll complete it, usually within a few business days. We’ll also tell you exactly where the SOC 2 program stands and when to expect the report.