Security

Elysian maintains a SOC 2 Type II attestation. Helping our customers improve their security and compliance posture starts with our own.

Governance

Elysian's Security and Privacy teams establish policies and controls, monitor compliance, and prove our security and compliance to third-party auditors.

Our policies are based on four foundational principles:

  • Access is limited to those with a legitimate business need, granted on the principle of least privilege.
  • Security controls are implemented and layered according to the principle of defense-in-depth.
  • Security controls are applied consistently across all areas of the enterprise.
  • Implementation of controls is iterative, continuously maturing across effectiveness, auditability, and reduced friction.

Data protection

Data at rest. All datastores with customer data are encrypted at rest. Sensitive data is protected with field-level encryption, meaning data is encrypted before it reaches the database. Neither physical nor logical access to the database is enough to read the most sensitive information.

Data in transit. Elysian uses industry-standard encryption everywhere data is transmitted over potentially insecure networks.

Secret management. Encryption keys are managed via Google Cloud Key Management Service (Cloud KMS). Cloud KMS stores key material in Hardware Security Modules (HSMs), preventing direct access by any individuals, including employees of Google and Elysian. Application secrets are encrypted and stored via Google Secret Manager, with access strictly limited.

Product security

Penetration testing. Elysian engages a leading penetration testing firm at least annually.

Vulnerability scanning. Vulnerability scanning is required at key stages of our Secure Development Lifecycle (SDLC), with regular security assessments at all stages.

Enterprise security

Endpoint protection. MDM software enforces secure configuration of endpoints, including disk encryption, screen lock configuration, and software updates.

Identity and access management. Employees are granted access to applications based on their role and automatically deprovisioned upon termination. Additional access requires approval according to per-application policies.

Vendor security. Elysian uses a risk-based approach to vendor security. Vendors are evaluated on access to customer and corporate data, integration with production environments, and potential impact to the Elysian brand. Each vendor receives an inherent risk rating, followed by a security evaluation to determine residual risk and an approval decision.

Threat awareness. Elysian's security team shares regular threat briefings with employees covering security and safety updates that require attention or action.