Security and compliance
Security and privacy, built in by default.
Elennai handles confidential docs for many tenants at once. Security is built in from day 1, not layered on afterwards. This is the contract.
Encryption
Defaults you can't forget.
Integration tokens: AES-256-GCM
The tokens for your connected tools (Notion, Google Drive, Slack, HubSpot and your own API credentials) are encrypted at rest with AES-256-GCM. Encryption keys can be rotated without you reconnecting anything.
Passwords we can't read
Your password is never stored in a form anyone can read, and nobody at Elennai can recover it - not support, not an engineer, not a stolen backup.
Verified billing and integration events
Events that arrive from Stripe or a connected tool are proven genuine before they can change anything on your account. Forged or replayed events are rejected outright.
TLS everywhere
HTTPS-only in production. Mixed content is blocked in strict mode. Certificate rotation handled by Railway/Cloudflare.
Multi-tenant isolation
One workspace can never see another.
Guarantees
- Complete data separation - your workspace's data is never visible to any other customer
- Your API keys and connected integrations are isolated and encrypted per workspace
- Fair-use protection - no other customer's traffic can affect your agent's availability
- Every request is verified against your workspace before any data is touched
- Your agent only answers on the domains you approve - nowhere else
- The AI never decides who it is talking to - identity is verified before the model is involved
AI-specific security
RAG as best practice.
We do not train on your data
We run no machine-learning pipeline of our own on customer data, and we never have. What Google Cloud may do with what we send it is governed by its terms for this service, and we will publish the applicable clause here rather than paraphrase it.
Prompt-injection guard
Anything in your knowledge base is treated as reference material, never as instructions. An uploaded document cannot take over the agent or pretend to speak for Elennai.
Token budget with hard cap
Every chat turn has a max-token budget. We drop the oldest history messages first; the system prompt + current message never exceed the limit.
Safety filter on output
The model provider's safety filter is active - a message that trips it comes back as an explicit error rather than an invented answer.
The model never writes a selector
- Every step in a guided action is derived from the real HTML on your page - captured by the recorder or found by a scan
- Nothing runs until you save it: a scan proposes, a recording drafts, you decide what enters the catalogue
- The model groups and names a flow, and is never asked to produce a target - so it cannot invent a control
- When no locator matches with confidence the run stops instead of clicking something else
Account security
Your account, and your way out.
Two-factor sign in
Any account can enrol an authenticator app and gets single-use recovery codes when it does; the second factor is then asked for at every sign-in. One honest detail: resetting your password does not clear the factor, so keep the recovery codes somewhere you can reach them.
Take your data with you
A workspace owner can request a full export - conversations, documents, contacts and settings. It is prepared in the background and delivered as a download link that expires, rather than a file that sits in an inbox forever.
Who did what, on the record
Sign-ins, plan changes, API-key generation and document uploads are written to an audit log, so a question about what happened to an account has an answer that is not somebody's memory.
Data residency
EU data residency.
EU-hosted backend
Node + Postgres + pgvector run on Railway in europe-west4 (Eemshaven, NL). Every boot asserts the live region matches the declared expectation; mismatch aborts the deploy.
EU model processing
Since 4 September 2026, the answers and the work of preparing your content for search both run on Google Cloud (Vertex AI) in europe-west4 (Eemshaven, NL), the same region as the database, rather than wherever Google happens to have capacity. Material prepared before that date was handled by a Google service outside the EU region. It has always been stored here and we did not redo it.
EU object storage
Uploaded docs are stored in S3-compatible object storage under EU jurisdiction (Cloudflare R2). A boot-time check asserts the declared storage jurisdiction matches the expected EU value before serving traffic.
Postgres backups
Railway runs daily point-in-time backups with a 7-day recovery window. Backup data stays in europe-west4 (Eemshaven, NL) alongside the live database.
Hosting, storage, backups and the model calls are pinned to the EU, and the region is verified on every deploy by an automated residency check that refuses to start the service if it is wrong. Google and Stripe belong to US-headquartered groups even though they process here, which is what the sub-processor page explains in full.
Compliance
What we have in place today.
A standard Data Processing Agreement (DPA) is available to Pro customers; Scale gets a custom MSA. EU data residency is built in.
Hosting, storage, backups and the model calls run in europe-west4 (Eemshaven, NL). Two of the providers doing that work belong to US-headquartered groups, Google and Stripe. The sub-processor page says what that means for you.
All logins, plan changes, API key generation, and document uploads are logged; audit-log entries are retained for 365 days.
Incident response
What happens if something goes wrong?
We log everything ourselves. Every request, login, and system event is captured in our own internal logs and watched around the clock. We don't rely on a third party to tell us something is wrong.
We contain it fast. We can invalidate every active session and cut outbound traffic instantly, so an issue stays small.
We tell you. If an incident affects your data, we inform you by email within 72 hours per GDPR - in plain language, with what happened and what we did about it.
Live uptime and open incidents are published at status.elenn.ai.
Questions about security?
We're happy to send the DPA, sub-processor list, or book an architecture walkthrough with your security team.