Security
Last updated: 2026-09-30
Elevay is built for founders who sell to security-conscious buyers. This page describes our technical and organisational measures as they are today, including where we still depend on providers outside the European Union.
1. Architecture and data residency
- Application: Next.js 15 on Vercel. Server functions run in Vercel's Frankfurt region (
fra1). The first check of each request (sign-in state and request limits per IP address) and static files are handled by Vercel's global edge network, at the location nearest to the visitor. - Primary database: PostgreSQL on Supabase, AWS region
eu-central-1(Frankfurt). - AI models: Microsoft Azure OpenAI Service is our primary provider for language models and text embeddings. Our Azure resource is in Sweden Central. Most of our model deployments are EU Data Zone deployments, which Microsoft processes inside its EU Data Boundary. Sequence preparation (planning the approach to an account, drafting the messages and checking them against our facts) uses a Global deployment, which Microsoft may process in any Azure region.
- Secondary AI providers: Anthropic and OpenAI, both in the United States, are used as fallback providers and by a few features that call them directly. Mistral AI (France) is available as an alternative, see section 8.
- Web research: to find company signals and fill in company details, we use the web search tool of Azure AI Foundry. It sends search queries about companies, such as a company's name and website, to Microsoft Bing. Microsoft states that its Data Protection Addendum does not apply to this data, and that these transfers occur outside its compliance and geographic boundaries.
- Speech-to-text: Deepgram (United States) transcribes live meeting capture and call recordings. Every transcription request we send to Deepgram opts out of Deepgram's Model Improvement Program. Live phone-call transcripts come from Twilio's built-in transcription, which sends the audio to Deepgram under Twilio's own terms. Meeting recordings that are uploaded or retrieved from Infomaniak kDrive are transcribed by OpenAI (United States), unless a self-hosted transcription server is configured.
- Email delivery: Resend (United States), for account emails (invitations, email verification, password resets) and for the outbound emails sent from connected mailboxes that have no SMTP server of their own, such as Google and Microsoft mailboxes. An email you send yourself from your Gmail or Outlook address goes out through Gmail or Outlook instead. Resend receives the content of each email it delivers.
- Product analytics: PostHog EU Cloud, loaded only after you accept analytics cookies, through a proxy on our own domain. Clicks are recorded without the text of what you click, and session recordings hide all text, form input values and images.
- Error reporting: Sentry, where enabled. Sentry stores events in its United States region unless a project uses its EU region (Frankfurt). Our browser Content Security Policy currently allows only Sentry's United States ingestion hosts.
- Background jobs: Inngest (United States) schedules and orchestrates our background jobs, such as sourcing, enrichment, email sending and mailbox sync. It receives their event payloads and step results, which can contain personal data.
See the Sub-processors page for the full vendor list, with where each one processes data and its exposure to the US CLOUD Act.
2. Encryption
- In transit: elevay.app is served over HTTPS, with an HSTS policy of two years that covers subdomains.
- At rest: Supabase encrypts the database at rest (AES-256).
- Field-level: OAuth access, refresh and ID tokens for Google and Microsoft accounts are encrypted with AES-256-GCM when they are stored. So are other integration secrets, such as SMTP passwords and third-party API keys, and two-factor secrets. The key is derived from an application secret kept outside the database. Tokens stored before this encryption was introduced stay as they were stored until a backfill rewrites them.
- Passwords: hashed with bcrypt (cost factor 12). New passwords, at sign-up, at a password reset and when you change your password in Settings → Security, are checked against Have I Been Pwned: only the first five characters of the password's SHA-1 hash leave our servers. If that service does not answer, the password is accepted.
3. Access control and tenant isolation
- Customer records carry their workspace identifier, and application queries are scoped to the signed-in user's workspace through a request-bound authorisation context.
- Role-based access control (admin, member, viewer). Admins can download the workspace's contacts, companies, deals, activities, notes and tasks, with their own profile, as a JSON file in Settings → Privacy & data. Any signed-in member, viewers included, can also export the workspace's contacts, companies, deals, activities, notes, tasks and outbound emails, including drafts and queued emails, as JSON or CSV.
- Sign-in with Google or Microsoft (OAuth), or with an email address and password. Our Privacy Policy and Sub-processors page describe the access we request from Google and Microsoft.
- Two-factor authentication with an authenticator app (TOTP) is available for email-and-password accounts in Settings → Security, with ten single-use recovery codes. Accounts that sign in with Google or Microsoft rely on that provider's two-factor settings.
4. Application security
- A Content Security Policy limits the hosts the browser can connect to. Inline scripts are still allowed; moving to per-request nonces is planned.
- SSRF guards on server-side fetches of user-supplied URLs.
- Workspace-scoped queries on write paths, to prevent access to another workspace's records.
- Signature verification on Stripe, Resend, EmailEngine and Twilio webhooks.
- Scheduled job endpoints authenticated by a shared secret, compared in constant time.
- Prompt-injection mitigation: untrusted content (emails, meeting notes) is wrapped in tagged sections in AI prompts.
5. Backups and continuity
- The database is hosted on Supabase, and its backups follow our Supabase plan. We do not publish recovery time or recovery point objectives yet.
- Application code is kept in version control on GitHub.
6. Logging and monitoring
- Structured application logs (JSON) in Vercel's runtime logs.
- Error reporting through Sentry, where enabled. Before an error report is sent, a filter removes user details, cookie and Authorization headers, email addresses and key-like secrets. It does not remove the address of the page, which can hold a one-time code from a link we emailed, or the IP addresses that some of our own log messages contain. Our servers send performance measurements of one request in ten without this filter; browsers do not measure page loads for Sentry.
- An audit log of sensitive actions in each workspace: sign-ins and sign-outs, member role changes and deactivations, invitations, workspace settings, two-factor changes, password resets (with the IP address and browser user agent), edits to contacts, accounts and opportunities, and workspace data exports from Settings → Privacy & data (with the IP address).
- Actions by Elevay staff in our operator console, including reads of raw personal data, are recorded in a separate audit log.
- Our team also receives operating alerts in its Slack channel, where configured. For a customer workspace, an alert gives only the workspace's identifier or, when a connected mailbox stops syncing, that mailbox's address. Reading these alerts is not recorded in an audit log.
7. Sub-processors and data transfers
The Sub-processors page lists our sub-processors, with what each one does, where it processes data, its exposure to the US CLOUD Act and the status of its data processing agreement, with a legend of what each status means. We notify every customer in the app, with a notice at the top of the Elevay workspace, at least 30 days before a new sub-processor starts processing Customer Data, never by email; anyone else finds each change there, with the date it takes effect. Our Privacy Policy explains the safeguards for transfers outside the European Economic Area.
8. EU-only options
Mistral AI (France) is wired in as an alternative provider for language models and embeddings. It is a setting of the whole deployment, not a workspace option: contact contact@elevay.app if you need it. A stack run entirely by EU or Swiss providers, for hosting, database, transactional email and monitoring, is on our roadmap and not available today.
9. Compliance
- GDPR and Swiss nFADP: workspace data export in Settings → Privacy & data, a public sub-processor list, and data processing terms for customers in our Terms of Service. Our internal record of processing activities, data protection impact assessment for AI processing and incident response plan date from May 2026, before our move to Azure OpenAI, and are due for an update. In September 2026 we added our AI demo to the record and to the assessment.
- Personal data breaches: if a breach affects customer data, we notify the customer without undue delay, as set out in our data processing terms.
- Certifications: we hold no security certification today. ISO/IEC 27001 and SOC 2 are on our roadmap.
10. Reporting a vulnerability
Email contact@elevay.app with details. We acknowledge within 24 hours and aim to issue a fix within 14 days for critical findings. We do not currently run a paid bug bounty but we credit researchers publicly with their consent.