Trust

Security and compliance, built into the platform.

Your data stays in the EU — and ELIAN ships with the controls operations and procurement teams expect from a B2B platform.

Where your data lives

Sovereign data: your cloud, or your own four walls.

By default we run ELIAN as a managed service, hosted in the EU (Netherlands). But the entire hub is portable: deploy it into your own private cloud, or fully on-premises, so the platform lives exactly where your data-sovereignty rules require.

Managed EU cloud

We host it on Microsoft Azure in the Netherlands. Fastest to start, nothing to run yourself, EU-only data residency.

Your private cloud

Deploy the same hub into your own cloud tenant on Kubernetes, under your accounts, your network and your policies.

Fully on-premises

Run the whole hub on your own hardware: a self-contained Kubernetes cluster with local high-availability PostgreSQL and no dependency on external key vaults. Data never leaves your building.

EU-only data residency

Telemetry, video, tasks and alerts stay in the Netherlands. No cross-region replication, no US transfer.

GDPR alignment

We act as a data processor for customer telemetry and as a data controller for marketing-site visits. DPA available; per-org data-retention configurable per signal type.

ISO 27001 & SOC 2 compliant

Our security implements the ISO 27001:2022 controls and the SOC 2 Trust Services Criteria: access control, risk management, incident response and asset management. Our control list is available to customers on request.

Multi-factor authentication

Email-based 6-digit OTP with 10-minute expiry and resend cooldown. Account lockout after 5 failed attempts; bcrypt-12 password hashing with strength meter.

Six-tier RBAC

Viewer, Technician, Site Manager, Site Admin, Org Admin, Owner — plus custom role definitions with a permission-matrix UI. Per-site role assignment.

Encrypted secrets

RTSP camera credentials stored with AES-256-GCM. JWT access tokens (30 min) with rotation and refresh-token revocation; session inactivity timeout with countdown.

Audit log & event trail

System Event Log records every account, configuration and operator action. Grid / list / timeline views; acknowledgement; CSV export; per-event GeoIP-tagged login fingerprints.

Automated backups & retention

Daily PostgreSQL pg_dump (custom format, zstd-compressed) with configurable retention on Azure Cool tier. Per-signal retention rules via the admin UI.

An audit trail your regulator can read.

Every alert, acknowledgement, role change, login and configuration tweak lands in the system event log with timestamp, user, IP and GeoIP. Filter by time, severity or category, then export to CSV for compliance review.

Security your auditor will recognise.