Skip to content

Trust centre

Security you can check, not just read about.

How ELIZON is deployed, where your data goes, how we secure the platform and how it helps you meet your obligations — with the documents behind each answer.

COMPANY
EU-incorporated (Bulgaria)
DEPLOYMENT
Your servers, air-gapped or a cloud you choose
AUDIT
An audit log per organisation, and run traces

Deployment and data flows

Where your data goes, for each way of running ELIZON.

Your servers

Everything runs in your data centre. Outside connections only to model providers you approve.

Air-gapped

No outside connection at all. Models run on your own hardware.

Your cloud or a provider’s

Runs in a cloud region or a sovereign cloud you choose. Data stays in that region.

Security overview

How the platform is protected.

Short answers here; the security pack has the detail your review needs.

Identity and access

Members and roles per organisation and project, custom roles, two-factor sign-in, and sign-in with Google.

Tenant isolation

Each organisation’s data, users and limits are kept apart, including in multi-client installations.

Encryption

Public traffic uses HTTPS (TLS 1.2 or later) with HSTS, and voice media uses DTLS-SRTP. Credentials and secrets are encrypted at the application level with AES-256-GCM, under a master key held in a secrets manager. Other data relies on storage-level encryption from your hosting environment.

Logging and audit

Sign-ins, member and role changes, secrets and package installs go to a per-organisation audit log. Team and workflow runs keep a full trace. Usage exports as CSV or Parquet.

Secure development

Every change goes through a pull request with automated checks: secret scanning (gitleaks), dependency vulnerability audits (pnpm audit, pip-audit, Trivy) that block on high and critical issues, linting, type-checking and tests. Packages are signed with Ed25519.

Audit Log

Settings · Organisation

Example audit log entries
TimeActorEventDetails
09:14Maria Ivanovamember.role_changedEditor → Admin
09:20Petar Stoyanovsecret.rotatedCore banking API
10:02Elena Dimitrovapackage.updatedClaims intake 1.3.0

Team run trace · Mode Route · Total cost €0.031 · Duration 4.2s · Delegations 1

Example audit log and run trace

Governance evidence

What ELIZON records.

Every agent, team and workflow by project, the roles that can change and run it, review decisions and who made them, what it cost, and a trace of each team and workflow run.

Compliance mapping

How ELIZON helps you meet your obligations.

ELIZON provides controls and evidence; compliance remains your organisation’s responsibility.

How ELIZON helps with GDPR, DORA, NIS2 and the EU AI Act
FrameworkHow ELIZON helps
GDPRData stays on infrastructure you choose; data processing agreement; EU sub-processors.
DORASelf-hosted deployment and any model, supporting third-party risk management and exit plans.
NIS2EU-incorporated vendor; an audit log per organisation and a trace of every team and workflow run; controlled outside connections.
EU AI ActEvery agent, team and workflow listed by project, with human review steps and a trace of every team and workflow run.

Documents

The paperwork, in one place.

VULNERABILITY DISCLOSURE

Found a security issue?

Report it to security@elizon.ai. We publish our disclosure policyand a security.txt file.

THIS WEBSITE

We practise what we sell

This site is hosted in the EU on OVHcloud and loads no third-party trackers.

Security pack

Request the security pack.

We send it within one business day, under NDA if your process requires one.

Thank you. We’ll send the security pack within one business day.

We use your details only to reply to this request. See our privacy notice.