Security & data governance
Your data stays in your environment. Everything else follows from that.
This page describes how Elevariq handles access, data, and AI-specific risk on client engagements. It is written to be read by a security team, and to be answered against in a vendor assessment.
Operating principles
Six commitments that shape every engagement.
Your data stays in your environment
Systems are deployed into your cloud accounts, under your credentials and your vendor agreements. We do not create a copy of your operational data on infrastructure we control in order to deliver the work.
Minimum necessary access
Access is scoped to the systems a task requires, granted for the duration it is required, and revoked at the end of the engagement. Access is individually attributed, never shared.
No training on your data
Your content is not used to train or fine-tune models for any other client, and vendor configurations are set to exclude your data from provider training where the provider offers that control.
Human approval on consequential actions
Automated systems propose, and a person approves, wherever an action moves money, changes a customer record of record, or communicates a commitment on your behalf. Approval thresholds are agreed with you.
Separated environments
Development, staging, and production are separated, with production credentials held only where they are needed. Test data is synthetic or de-identified by default.
Documented, so you are not dependent on us
Architecture, credentials inventory, and runbooks are maintained throughout, so your team can operate, audit, or replace the system without our involvement.
AI-specific controls
The risks that are particular to language models.
Traditional application security still applies. These are the controls that exist because a model is involved.
Model and vendor selection
Model choice is a documented decision covering capability, cost, data handling terms, and regional availability, not a default. Where a provider's terms are unacceptable for your data class, we say so before it is used.
Retrieval boundaries
Knowledge systems are scoped to approved sources, and permissions are enforced at retrieval so a user cannot reach content through an assistant that they could not open directly.
Sensitive data handling
Personal and payment data are excluded from prompts and logs by default, with redaction applied before content reaches a model provider where the use case requires it.
Logging and retention
Prompt and response logging is configurable and agreed with you, including what is retained, for how long, and who can read it. Retention defaults to the shortest period that still allows debugging.
Evaluation before rollout
Systems are tested against a written evaluation set covering the questions and edge cases that matter, including the ones where the correct behaviour is to refuse or escalate.
Monitored after rollout
Failure modes, escalation rates, and unusual behaviour are monitored, with an agreed route for you to report a bad output and get it addressed.
Practice
How we work day to day.
Secure development
Peer-reviewed changes, dependency scanning, and secrets held in a managed secret store rather than in code or configuration files.
Credential hygiene
Multi-factor authentication on every account with access to client systems, hardware-backed where the platform supports it, and a documented offboarding process.
Subprocessors
A current list of the vendors involved in delivering your systems is available on request, with notice before a material change.
Incident response
A defined route for detection, containment, and notification. Where an incident affects your data, you are notified without undue delay with what is known, what is not yet known, and what is being done.
Continuity
Backups and recovery expectations are agreed per system and tested, and documentation is current enough that recovery does not depend on a single person.
Confidentiality
NDAs are signed before commercial detail is shared, and client work is not published, named, or used in marketing without written permission.
Available on request
Documentation for your vendor review.
Ask before you share anything. We would rather answer a security review early than discover a blocker after a kickoff date is set.
- Data processing agreement
- Subprocessor list
- Written security overview
- Completed security questionnaire
- Insurance certificates
- Business continuity summary
Which certifications does Elevariq hold?
Where is our data processed?
Can you complete our security questionnaire?
What happens to our data when the engagement ends?
Who on your side can see our systems?
Next step
Send us the questionnaire before the kickoff date.
If your organization has a vendor assessment process, we would rather start it now than at the point it delays delivery. Send the pack and we will return it completed, with honest answers on the controls we do not meet.
Security questions are answered by the people who would do the work, not a sales team.