Security & data governance

Your data stays in your environment. Everything else follows from that.

This page describes how Elevariq handles access, data, and AI-specific risk on client engagements. It is written to be read by a security team, and to be answered against in a vendor assessment.

Operating principles

Six commitments that shape every engagement.

Your data stays in your environment

Systems are deployed into your cloud accounts, under your credentials and your vendor agreements. We do not create a copy of your operational data on infrastructure we control in order to deliver the work.

Minimum necessary access

Access is scoped to the systems a task requires, granted for the duration it is required, and revoked at the end of the engagement. Access is individually attributed, never shared.

No training on your data

Your content is not used to train or fine-tune models for any other client, and vendor configurations are set to exclude your data from provider training where the provider offers that control.

Human approval on consequential actions

Automated systems propose, and a person approves, wherever an action moves money, changes a customer record of record, or communicates a commitment on your behalf. Approval thresholds are agreed with you.

Separated environments

Development, staging, and production are separated, with production credentials held only where they are needed. Test data is synthetic or de-identified by default.

Documented, so you are not dependent on us

Architecture, credentials inventory, and runbooks are maintained throughout, so your team can operate, audit, or replace the system without our involvement.

AI-specific controls

The risks that are particular to language models.

Traditional application security still applies. These are the controls that exist because a model is involved.

Model and vendor selection

Model choice is a documented decision covering capability, cost, data handling terms, and regional availability, not a default. Where a provider's terms are unacceptable for your data class, we say so before it is used.

Retrieval boundaries

Knowledge systems are scoped to approved sources, and permissions are enforced at retrieval so a user cannot reach content through an assistant that they could not open directly.

Sensitive data handling

Personal and payment data are excluded from prompts and logs by default, with redaction applied before content reaches a model provider where the use case requires it.

Logging and retention

Prompt and response logging is configurable and agreed with you, including what is retained, for how long, and who can read it. Retention defaults to the shortest period that still allows debugging.

Evaluation before rollout

Systems are tested against a written evaluation set covering the questions and edge cases that matter, including the ones where the correct behaviour is to refuse or escalate.

Monitored after rollout

Failure modes, escalation rates, and unusual behaviour are monitored, with an agreed route for you to report a bad output and get it addressed.

Practice

How we work day to day.

Secure development

Peer-reviewed changes, dependency scanning, and secrets held in a managed secret store rather than in code or configuration files.

Credential hygiene

Multi-factor authentication on every account with access to client systems, hardware-backed where the platform supports it, and a documented offboarding process.

Subprocessors

A current list of the vendors involved in delivering your systems is available on request, with notice before a material change.

Incident response

A defined route for detection, containment, and notification. Where an incident affects your data, you are notified without undue delay with what is known, what is not yet known, and what is being done.

Continuity

Backups and recovery expectations are agreed per system and tested, and documentation is current enough that recovery does not depend on a single person.

Confidentiality

NDAs are signed before commercial detail is shared, and client work is not published, named, or used in marketing without written permission.

Available on request

Documentation for your vendor review.

Ask before you share anything. We would rather answer a security review early than discover a blocker after a kickoff date is set.

  • Data processing agreement
  • Subprocessor list
  • Written security overview
  • Completed security questionnaire
  • Insurance certificates
  • Business continuity summary
Which certifications does Elevariq hold?
Elevariq is not currently certified to ISO 27001 or SOC 2. We are explicit about that rather than implying otherwise. Where your policy requires certified processing, we work inside your certified environment and under your controls, which is the arrangement most of our enterprise work already runs on.
Where is our data processed?
In the cloud accounts and regions you nominate. Where a use case requires a model provider, we select and configure providers that can process in your required region and confirm that in writing before use.
Can you complete our security questionnaire?
Yes. Send it with your vendor onboarding pack. If a control is one we do not meet, the response will say so and describe the compensating control rather than leaving the row ambiguous.
What happens to our data when the engagement ends?
Access is revoked, any working copies held for the engagement are deleted on a schedule agreed in the DPA, and written confirmation is provided. Your production data never leaves your environment in the first place.
Who on your side can see our systems?
Only the named delivery team, with access scoped to what their work requires. The team is named at kickoff and you are told before it changes.

Next step

Send us the questionnaire before the kickoff date.

If your organization has a vendor assessment process, we would rather start it now than at the point it delays delivery. Send the pack and we will return it completed, with honest answers on the controls we do not meet.

Security questions are answered by the people who would do the work, not a sales team.

Book a Call