Security and compliance

Security and privacy FAQ

Understand how Elba handles customer data, access, AI processing, and remediation.

Reviewed Sep 5, 2026 · Security

These answers summarize Elba's general security and data-handling principles. The enabled modules, integration authorization screen, customer agreement, and Data Processing Addendum determine the exact processing for a workspace.

Is Elba a data controller or processor?

Elba acts as a processor for personal data handled on a customer's behalf through the service and processes that data to provide the contracted service under documented customer instructions. Elba acts as a controller for limited business information it collects for its own purposes, such as account, contact, and billing administration.

What customer data does Elba store?

Elba applies data minimization and stores the data needed for the modules a customer enables. Depending on those modules, this can include:

  • Directory records such as provider user and group identifiers, names, email addresses, group membership, and the identifiers used to map provider accounts to Elba members. Depending on the provider, selected attributes can also include locale, location, account creation time, or a manager identifier.
  • Authentication and OAuth grant metadata.
  • Data Protection records such as a source object or message identifier, display name, source URL, timestamps, selected source metadata, relevant sharing principals, permission and content hashes, sensitivity categories and confidence, risk analysis, and issue status. The exact fields vary by connector and enabled capability.
  • Browser Security, awareness, phishing, and remediation metadata.

Connector-specific permissions and data access can differ. Review OAuth scopes and permissions, the relevant integration guide, and the live provider authorization screen before connecting a source.

Does Elba retain raw customer content used for AI analysis?

AI data handling is feature-specific and may involve different subprocessors and regions. Where Data Protection content analysis is enabled, raw content is processed only as needed for detection and is not retained in Elba's primary finding records. Those records contain hashes and the limited source and finding metadata needed to present, deduplicate, and audit the result. Content may be temporarily staged while processing completes.

Other AI-assisted features can process administrator-submitted prompts, source material, or files. Contact [email protected] for current subprocessor, region, retention, and transfer information for the feature you intend to use.

Browser Security has additional, capability-specific data-handling rules. See Browser extension capabilities for the current details.

Is customer data used to train AI models?

No. Elba does not use customer data to train or improve AI models.

How does Elba protect access and integration credentials?

  • Authentication is delegated to the customer's Google Workspace, Microsoft 365, or Okta identity provider.
  • Product access is scoped by workspace and role.
  • Database and application traffic is encrypted in transit.
  • Integration credentials and tokens are protected at rest and can be revoked through the relevant provider or integration flow.
  • Elba separates production environments and regional deployments.

The customer's identity-provider policy governs controls such as multifactor authentication for administrator and member sign-in.

Where is customer data processed?

Core customer data is hosted by OVHcloud for EU environments and Neon for US environments. Supporting storage, AI processing, and other subprocessors can involve different locations depending on the enabled modules. Core database hosting does not determine the location of every processing operation. Request the current subprocessor and transfer information from [email protected] for a contractual or security review.

Does connecting an integration enable automatic remediation?

No remediation is activated merely by connecting a source. Remediations are initiated by an administrator or member, or by a rule-based Playbook that a customer administrator explicitly configures and enables. Access Review revocations remain human-triggered.

How can I request security evidence or deletion of personal data?

  • For security reports, penetration-test material, compliance evidence, a questionnaire, or subprocessor information, contact [email protected]. Controlled documents may require organization verification or an NDA.
  • For access, correction, export, or deletion requests involving personal data, contact [email protected]. Elba may request information to verify the requester's identity or authority. The applicable agreement, DPA, and legal requirements govern retention and deletion.

On this page