Last updated: July 25, 2026
Security is not an afterthought at Eleva - it is built into every layer of our platform. We take the protection of your business data seriously and continuously improve our security posture.
This page describes the technical and organizational measures we have in place to protect your data.
Hosting: Eleva is hosted on a globally distributed cloud infrastructure with automatic HTTPS, DDoS protection, and 99.9%+ uptime.
Database: Your data is stored on a SOC 2 Type II certified database platform running on AWS. This provides:
Data in transit: All communication between your browser and Eleva is encrypted using TLS 1.2+ (HTTPS). We enforce HTTPS across all endpoints and use HSTS to prevent downgrade attacks.
Data at rest: All data stored in our database is encrypted at rest using AES-256 - the same standard used by financial institutions and government agencies.
Passwords: User passwords are hashed using bcrypt with a high work factor. We never store plain-text passwords.
Authentication: User authentication supports:
Row-Level Security (RLS): Row-level security policies ensure that each user can only access their own data - enforced at the database level, not just in application code.
Internal access: Eleva team member access to infrastructure is controlled by multi-factor authentication (MFA) and principle of least privilege.
When you use Eleva's AI features, your content (documents, queries, contract text) is transmitted to our AI processing provider for processing.
Magic Inbox and other automated ingestion sources introduce content from outside Eleva, so we treat it as untrusted by default:
We operate a responsible disclosure program. If you discover a security vulnerability in Eleva, please report it to us before public disclosure:
Email: security@appeleva.com
Please include:
We commit to:
We will not take legal action against researchers who follow responsible disclosure practices.
In the event of a security incident affecting your data:
We continuously work toward improving our compliance posture as the platform scales.
For security-related questions or to report a vulnerability:
Email: security@appeleva.com