Company · Data Security

Data Security

How ELTON isolates, encrypts, monitors and destroys customer data.

ONE SUBSCRIPTION PER CUSTOMER · DATA PATH FOR ONE ENGAGEMENTHandling of customer-provided documentation, code and vulnerability reportsYOUR SUBSCRIPTION · MICROSOFT AZURE · MICROSOFT ENTRA ID · NO OTHER PARTYYOUproduct documentation,source and firmware,vulnerability reportsTLS 1.2+DEDICATED STORAGEstorage account in yoursubscription, not sharedAES-256, DEK wrapped bya KEK in Azure Key Vaultcustomer key on requestshared with others: noISOLATED TEST COMPUTEharness runs inside thesubscription, deny-all firewallVPN, conditional access, MFAjust-in-time elevation (PIM)no copy leaves Azurepublic endpoints: nonePLATFORM RECORDfindings, test cases,ratings and evidenceretained for traceabilityraw inputs are notpart of the recordkept: results onlyCOMPLETIONsubscription and tenantdeleted at engagement endAzure cryptographic erasureand secure overwritemedia: NIST SP 800-88recoverable: noSubprocessors: Microsoft Azure, Microsoft 365 E5. No other supplier, no outsourced development, no AI provider receives customer data.encrypted in transitat rest, keys in Key Vaultused inside the tenant onlyretained as the recorddestroyed at completion
Data path for one engagement: encrypted in transit, encrypted at rest with keys in Key Vault, processed only inside the customer subscription, deleted with it at completion.
Section 1

Tenant isolation and access control

A dedicated Azure and Microsoft 365 subscription per customer.

Identity

Identity and privileged access

Microsoft Entra ID is the single source of truth for every identity, including vendors, and MFA is enforced for all users whether privileged or not. Administrative rights are granted by ticket with CISO approval, held just-in-time through Privileged Identity Management, and reviewed quarterly or on any role change. Two privileged accounts exist, one break-glass and one operations, and the sole domain administrator is a service account protected by LAPS.

Storage and keys

Encryption and key management

Data at rest is protected by Azure Storage encryption, Azure SQL transparent data encryption and Microsoft Purview Information Protection with AES-256. Each data encryption key is wrapped by a key encryption key that never leaves Azure Key Vault; Microsoft-managed keys rotate automatically and customer-managed keys, including HSM-backed keys, are available per customer with annual rotation. Key access is governed by RBAC and logged in Key Vault and Azure Monitor.

Network

Network access

Traffic between customers and the platform uses TLS 1.2 or later, with per-login session keys that expire after 30 minutes of inactivity. Test infrastructure has no public endpoints: engineers reach it over VPN under conditional access with MFA and device compliance checks, through Azure Bastion, behind instance-level firewalls that deny all by default. Internal dataflows never leave the Azure subscription.

Section 2

Data lifecycle and destruction

Inputs are deleted with the subscription; the record is retained.

Data class
Where it lives
Who can read it
What happens at completion
Product documentation
architecture, SBOM, threat model, QMS records
Dedicated storage in your subscription, AES-256 at rest, keys in Key Vault
Engineers assigned to the engagement, elevated just-in-time; the harness and local models inside the subscription
Destroyed with the subscription. Twin components derived from it stay in the record.
Source, firmware, binaries
Dedicated storage; unpacked only on isolated test compute in the subscription
Same as above; never leaves Azure, never sent to any model provider
Destroyed. Test cases and evidence that reference them stay.
Vulnerability reports
third-party, researcher, scanner output
Dedicated storage and the platform's finding pipeline
Assigned engineers; verification runs inside the subscription
Kept as findings with verification result and disposition; raw report destroyed.
Test artifacts
captures, memory dumps, logs
Isolated test compute in the subscription
Assigned engineers
Destroyed once the evidence they support is written to the record.
The record
findings, test cases, ratings, rationale, VEX
Platform database in your tenant, encrypted at rest with TDE, audited into Sentinel
Your users, by role; ELTON engineers with tenant access
Retained for the subscription term; reports delivered as PDF or CSV over encrypted email, SFTP or the portal.
Erasure

Subscription deletion and cryptographic erasure

At the end of an engagement the Azure subscription and tenant that held the customer's data are deleted under ELTON's formal data retention and disposal procedure, a control the SOC 2 auditor tested without exception. Erasure inside Azure is cryptographic: the platform's data encryption keys are unwrapped only by a key encryption key in Key Vault, so decommissioned storage is unreadable to anyone, ELTON and Microsoft included.

Physical media

Media sanitization

Microsoft sanitizes or destroys data-bearing devices that leave its datacenters under NIST SP 800-88, using cryptographic erasure and secure overwrite, and executes complete deletion of customer data on request and at contract termination. ELTON laptops are wiped through Microsoft 365 at end of life, and removable media is blocked by Intune and endpoint DLP.

Section 3

Subprocessors and supplier controls

Microsoft is the only subprocessor.

Provider
What it does
How it is governed
Microsoft Azure
Hosts the ELTON platform, per-customer subscriptions, storage, Key Vault, and the isolated compute that runs the testing harness and local models. The only subservice organization in ELTON's SOC 2 report.
Microsoft's SOC 2 report obtained and reviewed annually; complementary physical-access controls (CC6.4) assumed and monitored; standard agreement with confidentiality clauses
Microsoft 365 E5
Identity (Entra ID), email, documents, Intune device management, Purview DLP and Insider Risk for ELTON staff
Same annual SOC 2 review; DLP rules enabled and tested; engagement correspondence only, never product documentation, code or findings
Anyone else
None. No offshore staff, no contractors with data access, no outsourced code development, no analytics or support tooling with access to customer content
Supplier risk program aligned to ISO/IEC 27001 and NIST: due diligence before onboarding, security terms in every contract, right-to-audit, SOC 2 or ISO 27001 evidence reviewed annually
Section 4

Infrastructure security controls

Controls by layer, enforced through Azure Policy.

DEFENSE IN DEPTH · ONE VENDOR STACK, FIVE LAYERSControls by layer, as named in the SOC 2 report and vendor security responsesIDENTITYMicrosoft Entra ID, MFA forevery userConditional Access + devicecompliancePIM just-in-time elevation,quarterly access reviewsOne break-glass and one opsprivileged account, LAPSPERIMETERAzure Firewall, defaultdeny, allowlists,geofencingAzure Front Door WAF (OWASPTop Ten), rate limitingAzure DDoS ProtectionStandardDefender External AttackSurface ManagementNETWORK + COMPUTENSGs, Azure Bastion, VPNwith conditional accessCIS benchmarks andMicrosoft SecurityBaselines via Azure PolicyHardened images, secureboot, vTPM, monthlyinfrastructure scansDefender for Endpoint EDR,file integrity monitoring,tamper protectionDATAAES-256 at rest: Storageencryption, TDE, PurviewMIPDEK wrapped by KEK in AzureKey Vault, HSM availableTLS 1.2+ in transit,30-minute sessionsPurview DLP and InsiderRisk, labels Public toHighly ConfidentialDETECTION + RESPONSEMicrosoft Sentinel SIEM,immutable audit logs, 24/7alertingDefender for Cloud CSPM,Defender for Identity,Defender XDRIR plan on NIST SP 800-61and ISO/IEC 27035, 24-hourcustomer noticeMTTD under 1 hour, MTTRunder 4 hours for criticaldata spill
Baselines: CIS Benchmarks and Microsoft Security Baselines, monitored and remediated through Azure Policy and Defender for Cloud.
Endpoints

Endpoint protection

Every laptop runs Defender for Endpoint with EDR, file integrity monitoring and tamper protection, definitions updated several times a day, BitLocker full-disk encryption, Defender Application Control allow-listing and Intune compliance. Standard users have no local administrator rights, jailbroken or rooted devices are blocked, and mobile devices cannot connect to the solution at all.

Patching

Patch and vulnerability management

Patch management covers every layer, OS, middleware, application and database, through Windows Update for Business, Intune and Azure Update Management. Critical and actively exploited vulnerabilities are deployed within 24 to 48 hours, high within 7 days, medium in the next maintenance window. Cloud assets and endpoints are scanned continuously, with monthly infrastructure scans and real-time alerts on criticals.

Monitoring

Logging and monitoring

Every security-relevant event, access, account action and configuration change is logged to Microsoft Sentinel with immutability policies and restricted access, correlated with threat intelligence in Defender XDR, and alerted 24/7. Audit-processing failures raise their own alert. Privileged sessions are watched by Defender for Cloud and Purview Insider Risk Management, and all systems keep NTP-synchronized time.

Section 5

Secure development and platform testing

C# and .NET with React, under a secure development lifecycle.

Practice
What happens
Evidence
Threat-modeled design
Requirements start with STRIDE and dataflow threat modeling; secure architecture and compliance review before implementation
SSDLC procedure; documented application development practices (SOC 2 E-40)
Code review and scanning
Peer review with dual approval required before any merge to main in Azure DevOps; GitHub Advanced Security scans code and third-party dependencies continuously; SAST and DAST through Defender for DevOps before major changes
Automated scanning tested (E-38); change audit trail with author, date, purpose, result and approver (E-45)
Segregation of duties
Developers cannot deploy; engineers who implement changes are separate roles. Development, test and production are logically segregated and developers have no access to production instances. Production data is never used in non-production environments
SoD tested in Azure subscription settings (E-41); environment segregation tested (E-39)
Controlled release
ITIL-aligned change management: minor changes through automated testing and peer review, major changes through a Change Advisory Board with impact assessment, rollback plan and sign-off. Only signed-off artifacts promote through CI/CD; no direct changes in production; critical and high findings fixed before release
Change tickets sampled by the auditor; deployment logs in Sentinel and version control
Application hardening
Input validation, ORM and stored procedures, anti-CSRF tokens with same-site cookies, content security policy and output encoding, all behind Azure WAF rules for the OWASP Top Ten
Annual penetration test findings tracked to remediation by criticality (E-19, E-20)
Independent testing
Annual third-party penetration test by Level Nine Group across external footprint, application code and infrastructure configuration, black-box and gray-box, plus quarterly vulnerability assessments and ad hoc tests for major changes. The most recent engagement returned only informational and low findings
Penetration test results inspected by the auditor (E-19)
Section 6

AI usage and data boundaries

Customer data never leaves the subscription for any model.

%s
Customer data enters the subscription and is not sent to any model provider. FDA-read decisions are produced by the deterministic layer.
Private AI providers

Frontier model use

ELTON uses OpenAI and Anthropic models to help write and review the code of the testing harness and pipeline. The inputs are ELTON's own code, specifications and tests. Customer documentation, code, findings and device identifiers are never sent, and the pipeline itself is not a prompt. A pipeline, not a prompt →

Local models

Locally hosted open-weight models

Digital twinning, exploitability analysis, text drafting and path and rating candidates run on open-source, open-weight models hosted on ELTON compute inside the subscription. The weights are static files. They are not connected to the organization that published them, they make no outbound calls, and there is no one on the other end to obtain access to what they process.

FDA decisions

Deterministic decision layer

ELTON has to produce traceable results and defensible justifications, so ratings use the qualified MDDT CVSS rubric, exploitability verdicts carry the test case that proves them, and dispositions carry a written rationale. AI is confined to work where FDA does not require a defensible decision, and a person reviews every AI-assisted output before it reaches you.

Section 7

Incident response, personnel and governance

NIST SP 800-61 and ISO/IEC 27035; 24-hour customer notification.

Incident response

Incident response

Every incident is documented and logged in Microsoft Sentinel. The plan covers identification, analysis, communication protocols for internal and external stakeholders, and lessons learned, with a mean time to detect under one hour and a mean time to respond under four hours for a critical data spill. Tabletop exercises and red team simulations run at least annually. Cyber insurance is maintained, and Purview eDiscovery supports a litigation hold on one tenant without freezing any other.

People

Personnel security

Every hire passes a criminal background check, signs a nondisclosure agreement and the employee handbook, and completes security awareness training at least annually covering acceptable use, phishing and social engineering, MFA and passwords, device security, data classification and incident reporting, with secure-coding modules for developers. Access is removed the moment a departure is notified, and devices are wiped. A CISO owns the security program; a designated Data Protection Officer owns privacy.

Governance

Governance and risk management

A formal information protection program based on the NIST Cybersecurity Framework is reviewed and updated at least annually, inside an ISMS aligned to ISO/IEC 27001:2022. Risk is assessed with NIST SP 800-30 across financial, operational, compliance, strategic and reputational categories, with plans of mitigation owned by leadership. Internal audits cover access, assets, patching, incident response, network, data protection and logging against ISO 27001, NIST CSF and CIS Controls. A business continuity plan is tabletop-tested annually and the CEO reports on objectives at a monthly all-hands.

Section 8

SOC 2 Type II attestation

IS Partners, LLC; June 1 to August 31, 2025; no exceptions noted.

AICPA SOC 2 Type II
ReportSOC 2 Type II, Security trust services criteria
Service auditorIS Partners, LLC, Dresher, Pennsylvania
PeriodJune 1, 2025 through August 31, 2025; report dated January 30, 2026
Result45 control activities tested, no exceptions noted, no security incidents identified
Subservice organizationMicrosoft Azure (infrastructure cloud hosting)
Criteria family
Controls tested
Result
CC1 · Control environment
Background checks, NDAs, handbook acknowledgement, disciplinary process, annual performance evaluations, CISO ownership, NIST CSF program reviewed annually, org chart, monthly all-hands, annual security training (E-1 to E-10)
No exceptions noted. Hiring controls could not be sampled because there were no new hires in the period.
CC2 · Communication
Policies and architecture documentation on the internal repository, asset inventory with owners, incident communication protocols, SLAs with automated postmarket alerting (E-11 to E-17)
No exceptions noted.
CC3, CC4 · Risk and monitoring
Annual risk assessment across five risk categories, annual penetration test with findings tracked to remediation, continuous vulnerability scanning of cloud assets and endpoints (E-18 to E-21)
No exceptions noted.
CC5 · Control activities
Business continuity plan with annual tabletop, firewall policy enforcement, encryption at rest and TLS 1.2 in transit, antivirus, BitLocker, infrastructure monitoring, Defender for Cloud alerting (E-22, E-31 to E-37)
No exceptions noted.
CC6 · Logical and physical access
MFA on every Entra-connected endpoint, customer access limited to ELTON staff and customer administrators, approved access changes, same-day termination, annual review of Microsoft's SOC 2, data classification, formal retention and disposal procedure, production segregated from non-production, Microsoft 365 DLP (E-23 to E-30, E-39, E-44)
No exceptions noted.
CC7 · System operations
Incident response plan with identification, analysis, communication and lessons learned; incidents logged in Sentinel; infrastructure and security monitoring with alerting (E-15, E-16, E-36, E-37)
No exceptions noted. No security incidents identified in the period.
CC8 · Change management
Documented development practices, automated code scanning, segregation of developers from deployers, full change audit trail with approver (E-38 to E-41, E-45)
No exceptions noted.
CC9 · Risk mitigation
Cyber insurance, standard third-party agreements with confidentiality clauses, annual subservice SOC 2 review (E-28, E-42, E-43)
No exceptions noted.
Scope. ELTON's controls over the platform and the people who operate it, with Microsoft Azure's physical-access controls (CC6.4) treated as complementary subservice controls. The report, the vendor questionnaire responses behind this page and the penetration test executive summary are available under NDA.
Section 9

Review materials

Available under NDA before any data is shared.

Item
Contents
Form
SOC 2 Type II report
Auditor opinion, management assertion, system description, 45 tested controls with results, TSC reference table
PDF, 40 pages
Vendor security questionnaire
Responses across isolation, storage, encryption, retention, access control, malware, network, incident process, change control, training, continuity, suppliers, privacy, compliance, governance and risk
Spreadsheet; customer templates also completed on request
Penetration test summary
Executive summary and remediation responses from the most recent independent test
PDF
Architecture walkthrough
Subscription layout, dataflows, key management and the test harness boundary for your engagement
Live session
Questions

Frequently asked questions

Is ELTON SOC 2 certified?

ELTON holds a SOC 2 Type II report on the Security trust services criteria, examined by IS Partners, LLC for the period June 1 through August 31, 2025 and issued January 30, 2026. Forty-five control activities were tested with no exceptions noted and no security incidents identified in the period. The report is shared with customers and prospects under NDA.

Where does my data physically live?

In dedicated storage inside an Azure subscription created for your engagement, in your geography, encrypted at rest with AES-256 and readable only by test compute running inside that subscription. Storage is not shared with any other customer and no copy is made outside Microsoft Azure.

What does destroyed at completion mean in practice?

The Azure subscription and tenant that held the engagement are deleted under ELTON's formal retention and disposal procedure, which the SOC 2 auditor tested without exception. Azure's envelope encryption means the data encryption keys can only be unwrapped by a key encryption key held in Key Vault, so decommissioned storage is cryptographically unreadable, and Microsoft sanitizes physical media under NIST SP 800-88 with cryptographic erasure and secure overwrite.

What does ELTON keep after a test?

The record: findings, test cases, ratings, evidence and dispositions, because FDA traceability depends on it. The raw inputs you provided, such as documentation, source and firmware images, are not part of that record and are destroyed with the engagement subscription.

Who are your subprocessors?

Microsoft only: Microsoft Azure for the platform and the internal testing infrastructure, and Microsoft 365 E5 for identity, email, documents and device management. Azure is the single subservice organization in ELTON's SOC 2 report and its SOC 2 is reviewed annually. There is no outsourced development, no contractor with data access, and no AI provider that receives customer data.

Do you support customer-managed keys and single sign-on?

Yes to both. Per-customer encryption keys can be held in Azure Key Vault or an HSM under your control, with annual rotation and Key Vault access logging. Authentication is through Microsoft Entra ID, which federates with your identity provider over SAML 2.0, OIDC or ADFS, and MFA is enforced for every user regardless of role.

Does customer data ever reach OpenAI or Anthropic?

No. ELTON uses frontier model APIs to help engineers write the code of the testing harness, and the inputs to that work are ELTON's own code, specifications and tests. Customer data is processed only by open-weight models hosted on ELTON compute inside the tenant, with no vendor account, no telemetry and no outbound model calls.

If AI is probabilistic, how is the output FDA-defensible?

Because the decisions FDA reads are not made by AI. Ratings come from the qualified MDDT CVSS rubric, exploitability verdicts come with the test case that proves them, and dispositions carry a written rationale. AI is used where a defensible decision is not required, such as drafting text or proposing candidate paths for verification, and every AI-assisted output is reviewed by a person before it reaches you.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI MedDevice PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
EnterpriseStartups / SMBs Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
One Solution Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionAI Inside the ProductSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsData SecurityContact Meet ELTON