Security and privacy FAQ
Understand how Elba handles customer data, access, AI processing, and remediation.
These answers summarize Elba's general security and data-handling principles. The enabled modules, integration authorization screen, customer agreement, and Data Processing Addendum determine the exact processing for a workspace.
Is Elba a data controller or processor?
Elba acts as a processor for personal data handled on a customer's behalf through the service and processes that data to provide the contracted service under documented customer instructions. Elba acts as a controller for limited business information it collects for its own purposes, such as account, contact, and billing administration.
What customer data does Elba store?
Elba applies data minimization and stores the data needed for the modules a customer enables. Depending on those modules, this can include:
- Directory identities, group membership, and the identifiers needed to map provider records to Elba members.
- Authentication and OAuth grant metadata.
- Application, file, document, or sharing metadata needed to identify and explain a security finding.
- Browser Security, awareness, phishing, and remediation metadata.
Connector-specific permissions and data access can differ. Review OAuth scopes and permissions, the relevant integration guide, and the live provider authorization screen before connecting a source.
Does Elba retain raw customer content used for AI analysis?
Some customer-configured detection workflows process limited content to classify a potential finding. Where AI content analysis is used, Elba does not retain the raw customer content after that processing. It keeps the limited finding and source metadata needed to present, deduplicate, and audit the result.
Browser Security has additional, capability-specific data-handling rules. See Browser extension capabilities for the current details.
Is customer data used to train AI models?
No. Elba does not use customer data to train or improve AI models.
How does Elba protect access and integration credentials?
- Authentication is delegated to the customer's Google Workspace, Microsoft 365, or Okta identity provider.
- Product access is scoped by workspace and role.
- Database and application traffic is encrypted in transit.
- Integration credentials and tokens are protected at rest and can be revoked through the relevant provider or integration flow.
- Elba separates production environments and regional deployments.
The customer's identity-provider policy governs controls such as multifactor authentication for administrator and member sign-in.
Where is customer data processed?
Core production data is stored in the region configured for the customer deployment. Supporting services and subprocessors can vary with the enabled modules and region. Request the current subprocessor and transfer information from [email protected] for a contractual or security review.
Does connecting an integration enable automatic remediation?
No remediation is activated merely by connecting a source. Remediations are initiated by an administrator or member, or by a rule-based Playbook that a customer administrator explicitly configures and enables. Access Review revocations remain human-triggered.
How can I request security evidence or deletion of personal data?
- For security reports, penetration-test material, compliance evidence, a questionnaire, or subprocessor information, contact [email protected]. Controlled documents may require organization verification or an NDA.
- For access, correction, export, or deletion requests involving personal data, contact [email protected]. Elba may request information to verify the requester's identity or authority. The applicable agreement, DPA, and legal requirements govern retention and deletion.