Trust Center

How Elixion handles security and your data

This page is the single place for security questions about Elixion. If you need anything that is not covered here, email security@elixion.ai.

Compliance posture

  • SOC 2 Type II — fieldwork in preparation; report available under NDA once issued. Email security@elixion.ai to request the current readiness summary.
  • GDPR / UK GDPR / CCPA — we operate as a processor under your control. See our DPA template (linked below) for the contractual terms.
  • Annual third-party penetration test — report under NDA on request.

How your data is protected

  • Encryption in transit — TLS 1.2+ for all customer traffic.
  • Encryption at rest — AES-256 on the database; integration tokens, OAuth secrets, and webhook tokens are additionally Fernet-encrypted with rotation support.
  • Access — least privilege, MFA on every administrative login, JWT rotation + per-session revocation.
  • Audit trail — every authenticated state change is recorded in an append-only audit log with daily off-host export to an Object-Lock-protected S3 bucket.
  • Backups — daily encrypted database backups, 30-day retention, restore drill run quarterly.
  • Right to be deleted — every user can request account deletion via POST /api/v1/users/me/erase. PII is anonymized, credentials revoked.

Sub-processors

We use a small number of well-known infrastructure and SaaS sub-processors. The current list, with region, purpose, and DPA status, is in our repository:

docs/sub-processors.md on GitHub.

We commit to giving at least 30 days' notice before adding or replacing a sub-processor. To receive notifications, email security@elixion.ai with the subject “sub-processor notifications”.

Policies

Report a concern (whistleblower channel)

We take ethics, safety, and security concerns seriously, and we protect anyone reporting in good faith from retaliation. You have four routes; use whichever you are most comfortable with.

  1. Tell your manager (for Elixion personnel) or our CEO directly.
  2. Email ethics@elixion.ai — goes to the CEO and the board chair. Acknowledgement within two business days.
  3. Anonymous form — third-party hosted, strips identifying metadata. (Form provisioning in progress; until live, the email channel above or a paper letter to the address on the policy page is the anonymous fallback.)
  4. External authorities — nothing in our policies restricts you from reporting suspected illegal conduct to a regulator or law-enforcement agency.

Full policy: Code of Conduct + Ethics + Whistleblower Policy.

Request the SOC 2 report or a security questionnaire

Both are available under a mutual NDA. Email security@elixion.ai with your company name and a contact. We typically respond within two business days.