Skip to main content

Security & Governance

Security & Trust

Built by engineers. Designed for reliable, transparent, and secure operations. We implement rigorous technical controls, strict environment isolation, and disciplined access policies to safeguard the infrastructure and data you entrust to us.

Our Engineering Pledge

Actual Technical Safeguards Over Vanity Badges

We believe true security is found in configuration discipline, minimal attack surfaces, verified backups, and continuous monitoring. We do not make unsubstantiated certification claims; instead, we invite your technical leadership to review our runbooks, architectural designs, and access governance firsthand.

You retain 100% ownership of your cloud accounts and code
All engineers authenticate via hardware keys or TOTP MFA
Immutable backups tested on predictable schedules
Air-gapped development, staging, and production tiers

Operational Rigor

Our Security Controls & Practices

How we protect client systems, manage access, safeguard credentials, and ensure operational continuity.

Access Control & Principle of Least Privilege

Engineers only receive access to the specific resources required to execute an assigned task. Access is time-bound, role-scoped, and reviewed regularly.

  • Role-Based Access Control (RBAC) across all systems and repositories
  • Immediate revocation upon task completion or role change
  • No permanent superuser or root account usage for daily operations
  • Segregated client environments with zero lateral connectivity

MFA & Secure Credential Management

Passwords are never shared or hardcoded. All authentication requires hardware or TOTP multi-factor verification.

  • Hardware security keys (FIDO2/WebAuthn) or TOTP mandatory across all staff accounts
  • Enterprise secrets vaults (e.g., HashiCorp Vault, AWS Secrets Manager, 1Password Teams)
  • Automated secret scanning on Git commits to prevent token leakage
  • Regular rotation schedules for SSH keys and API access tokens

Environment Separation

Strict physical and logical barriers separate development, staging, and production environments.

  • Production environments run in dedicated VPCs/accounts with distinct access controls
  • Sanitized data sets for development; real customer PII is never loaded into dev environments
  • Independent encryption keys for separate application environments
  • Automated CI/CD promotion gates requiring manual approval for production deploys

Logging, Auditing & Real-Time Monitoring

Every administrative command, deployment, and network request produces immutable audit logs.

  • Centralized log aggregation with tamper-resistant retention policies
  • Continuous alerting on unusual authentication spikes or privilege escalations
  • Session recording and command logging for bastion/SSH access
  • Comprehensive telemetry covering CPU, disk I/O, error rates, and ingress traffic

Secure Remote Access & Zero Trust

Access to infrastructure requires encrypted tunnels, identity verification, and device posture checks.

  • WireGuard and IPsec VPNs with strict IP allowlisting for administrative consoles
  • Bastion jump-hosts with public keys and MFA verification
  • Direct internet exposure for internal management tools is strictly prohibited
  • Encrypted transport (TLS 1.3) enforced for all operational communication

Data Protection & Encryption

Client data is safeguarded at every phase of the lifecycle, both in transit and at rest.

  • AES-256 encryption at rest for databases, object storage, and disk volumes
  • TLS 1.2+ mandatory for all external and internal API communications
  • Automated sanitization and cryptographic zeroing on decommissioned storage
  • Client retains full legal ownership and control over all proprietary data

Personnel & Engineering Security Practices

Our team operates under strict confidentiality, security training, and clean-desk policies.

  • Comprehensive background checks and signed Non-Disclosure Agreements (NDAs)
  • Continuous security training on phishing prevention, social engineering, and safe coding
  • Mandatory full-disk encryption (FileVault/BitLocker) on all company workstations
  • Strict policy against using unapproved third-party AI tools with client source code or data

Backup, Snapshot & Disaster Recovery

Tested resilience against hardware failure, ransomware, and human error.

  • Automated 3-2-1 backup topology with offsite, air-gapped immutable storage
  • Regular automated test restores to verify database integrity
  • Explicit recovery time (RTO) and recovery point (RPO) targets agreed with clients
  • Documented disaster recovery failover runbooks tested semi-annually

Client Access & Credential Governance

Transparent, client-owned access structures that keep you in control at all times.

  • We encourage clients to provision Elvtera accounts inside their own identity providers
  • You retain master billing and root credentials on all cloud providers
  • Auditable access logs available to client security officers upon request
  • Complete handover runbooks enabling any qualified third party to assume operations

Operational Playbook

Incident Response & Escalation Protocol

In the event of an operational anomaly, security event, or service degradation, our team initiates a structured containment process.

PHASE 1

Detect & Triage

Automated monitoring detects threshold anomalies or unauthorized access attempts. Alert is routed to on-call engineers.

PHASE 2

Isolate & Contain

Impacted nodes or access tokens are isolated to prevent lateral movement while maintaining evidence integrity.

PHASE 3

Remediate & Restore

Root vulnerability is patched, system binaries verified against checksums, and service restored in staging before production cutover.

PHASE 4

Post-Mortem & Hardening

A transparent, blameless post-mortem report is delivered to the client detailing timeline, root cause, and permanent hardening steps taken.

Work with a team that respects your operational security.

Schedule a technical conversation to review our security controls, NDA frameworks, and infrastructure management standards.