Trust centre
Security you can check, not just read about.
How ELIZON is deployed, where your data goes, how we secure the platform and how it helps you meet your obligations — with the documents behind each answer.
- COMPANY
- EU-incorporated (Bulgaria)
- DEPLOYMENT
- Your servers, air-gapped or a cloud you choose
- AUDIT
- An audit log per organisation, and run traces
Deployment and data flows
Where your data goes, for each way of running ELIZON.
Your servers
Everything runs in your data centre. Outside connections only to model providers you approve.
Air-gapped
No outside connection at all. Models run on your own hardware.
Your cloud or a provider’s
Runs in a cloud region or a sovereign cloud you choose. Data stays in that region.
Security overview
How the platform is protected.
Short answers here; the security pack has the detail your review needs.
Identity and access
Members and roles per organisation and project, custom roles, two-factor sign-in, and sign-in with Google.
Tenant isolation
Each organisation’s data, users and limits are kept apart, including in multi-client installations.
Encryption
Public traffic uses HTTPS (TLS 1.2 or later) with HSTS, and voice media uses DTLS-SRTP. Credentials and secrets are encrypted at the application level with AES-256-GCM, under a master key held in a secrets manager. Other data relies on storage-level encryption from your hosting environment.
Logging and audit
Sign-ins, member and role changes, secrets and package installs go to a per-organisation audit log. Team and workflow runs keep a full trace. Usage exports as CSV or Parquet.
Secure development
Every change goes through a pull request with automated checks: secret scanning (gitleaks), dependency vulnerability audits (pnpm audit, pip-audit, Trivy) that block on high and critical issues, linting, type-checking and tests. Packages are signed with Ed25519.
| Time | Actor | Event | Details |
|---|---|---|---|
| 09:14 | Maria Ivanova | member.role_changed | Editor → Admin |
| 09:20 | Petar Stoyanov | secret.rotated | Core banking API |
| 10:02 | Elena Dimitrova | package.updated | Claims intake 1.3.0 |
Team run trace · Mode Route · Total cost €0.031 · Duration 4.2s · Delegations 1
Governance evidence
What ELIZON records.
Every agent, team and workflow by project, the roles that can change and run it, review decisions and who made them, what it cost, and a trace of each team and workflow run.
Compliance mapping
How ELIZON helps you meet your obligations.
ELIZON provides controls and evidence; compliance remains your organisation’s responsibility.
| Framework | How ELIZON helps |
|---|---|
| GDPR | Data stays on infrastructure you choose; data processing agreement; EU sub-processors. |
| DORA | Self-hosted deployment and any model, supporting third-party risk management and exit plans. |
| NIS2 | EU-incorporated vendor; an audit log per organisation and a trace of every team and workflow run; controlled outside connections. |
| EU AI Act | Every agent, team and workflow listed by project, with human review steps and a trace of every team and workflow run. |
Documents
The paperwork, in one place.
- Request the Security overview →
Security overview
Architecture, access control and operations summary.
- Request the Data processing agreement →
Data processing agreement
Template DPA for customers and partners.
- Request the Sub-processor list →
Sub-processor list
Every third party involved, and where it is based.
- Request the EU data residency statement →
EU data residency statement
Where data is stored and processed in each deployment option.
- Request the full security pack →
Full security pack
Detailed architecture and controls. On request.
VULNERABILITY DISCLOSURE
Found a security issue?
Report it to security@elizon.ai. We publish our disclosure policyand a security.txt file.
THIS WEBSITE
We practise what we sell
This site is hosted in the EU on OVHcloud and loads no third-party trackers.
Security pack
Request the security pack.
We send it within one business day, under NDA if your process requires one.
Thank you. We’ll send the security pack within one business day.