How ELTON isolates, encrypts, monitors and destroys customer data.
A dedicated Azure and Microsoft 365 subscription per customer.
Microsoft Entra ID is the single source of truth for every identity, including vendors, and MFA is enforced for all users whether privileged or not. Administrative rights are granted by ticket with CISO approval, held just-in-time through Privileged Identity Management, and reviewed quarterly or on any role change. Two privileged accounts exist, one break-glass and one operations, and the sole domain administrator is a service account protected by LAPS.
Data at rest is protected by Azure Storage encryption, Azure SQL transparent data encryption and Microsoft Purview Information Protection with AES-256. Each data encryption key is wrapped by a key encryption key that never leaves Azure Key Vault; Microsoft-managed keys rotate automatically and customer-managed keys, including HSM-backed keys, are available per customer with annual rotation. Key access is governed by RBAC and logged in Key Vault and Azure Monitor.
Traffic between customers and the platform uses TLS 1.2 or later, with per-login session keys that expire after 30 minutes of inactivity. Test infrastructure has no public endpoints: engineers reach it over VPN under conditional access with MFA and device compliance checks, through Azure Bastion, behind instance-level firewalls that deny all by default. Internal dataflows never leave the Azure subscription.
Inputs are deleted with the subscription; the record is retained.
At the end of an engagement the Azure subscription and tenant that held the customer's data are deleted under ELTON's formal data retention and disposal procedure, a control the SOC 2 auditor tested without exception. Erasure inside Azure is cryptographic: the platform's data encryption keys are unwrapped only by a key encryption key in Key Vault, so decommissioned storage is unreadable to anyone, ELTON and Microsoft included.
Microsoft sanitizes or destroys data-bearing devices that leave its datacenters under NIST SP 800-88, using cryptographic erasure and secure overwrite, and executes complete deletion of customer data on request and at contract termination. ELTON laptops are wiped through Microsoft 365 at end of life, and removable media is blocked by Intune and endpoint DLP.
Microsoft is the only subprocessor.
Controls by layer, enforced through Azure Policy.
Every laptop runs Defender for Endpoint with EDR, file integrity monitoring and tamper protection, definitions updated several times a day, BitLocker full-disk encryption, Defender Application Control allow-listing and Intune compliance. Standard users have no local administrator rights, jailbroken or rooted devices are blocked, and mobile devices cannot connect to the solution at all.
Patch management covers every layer, OS, middleware, application and database, through Windows Update for Business, Intune and Azure Update Management. Critical and actively exploited vulnerabilities are deployed within 24 to 48 hours, high within 7 days, medium in the next maintenance window. Cloud assets and endpoints are scanned continuously, with monthly infrastructure scans and real-time alerts on criticals.
Every security-relevant event, access, account action and configuration change is logged to Microsoft Sentinel with immutability policies and restricted access, correlated with threat intelligence in Defender XDR, and alerted 24/7. Audit-processing failures raise their own alert. Privileged sessions are watched by Defender for Cloud and Purview Insider Risk Management, and all systems keep NTP-synchronized time.
C# and .NET with React, under a secure development lifecycle.
Customer data never leaves the subscription for any model.
ELTON uses OpenAI and Anthropic models to help write and review the code of the testing harness and pipeline. The inputs are ELTON's own code, specifications and tests. Customer documentation, code, findings and device identifiers are never sent, and the pipeline itself is not a prompt. A pipeline, not a prompt →
Digital twinning, exploitability analysis, text drafting and path and rating candidates run on open-source, open-weight models hosted on ELTON compute inside the subscription. The weights are static files. They are not connected to the organization that published them, they make no outbound calls, and there is no one on the other end to obtain access to what they process.
ELTON has to produce traceable results and defensible justifications, so ratings use the qualified MDDT CVSS rubric, exploitability verdicts carry the test case that proves them, and dispositions carry a written rationale. AI is confined to work where FDA does not require a defensible decision, and a person reviews every AI-assisted output before it reaches you.
NIST SP 800-61 and ISO/IEC 27035; 24-hour customer notification.
Every incident is documented and logged in Microsoft Sentinel. The plan covers identification, analysis, communication protocols for internal and external stakeholders, and lessons learned, with a mean time to detect under one hour and a mean time to respond under four hours for a critical data spill. Tabletop exercises and red team simulations run at least annually. Cyber insurance is maintained, and Purview eDiscovery supports a litigation hold on one tenant without freezing any other.
Every hire passes a criminal background check, signs a nondisclosure agreement and the employee handbook, and completes security awareness training at least annually covering acceptable use, phishing and social engineering, MFA and passwords, device security, data classification and incident reporting, with secure-coding modules for developers. Access is removed the moment a departure is notified, and devices are wiped. A CISO owns the security program; a designated Data Protection Officer owns privacy.
A formal information protection program based on the NIST Cybersecurity Framework is reviewed and updated at least annually, inside an ISMS aligned to ISO/IEC 27001:2022. Risk is assessed with NIST SP 800-30 across financial, operational, compliance, strategic and reputational categories, with plans of mitigation owned by leadership. Internal audits cover access, assets, patching, incident response, network, data protection and logging against ISO 27001, NIST CSF and CIS Controls. A business continuity plan is tabletop-tested annually and the CEO reports on objectives at a monthly all-hands.
IS Partners, LLC; June 1 to August 31, 2025; no exceptions noted.

Available under NDA before any data is shared.
Is ELTON SOC 2 certified?
ELTON holds a SOC 2 Type II report on the Security trust services criteria, examined by IS Partners, LLC for the period June 1 through August 31, 2025 and issued January 30, 2026. Forty-five control activities were tested with no exceptions noted and no security incidents identified in the period. The report is shared with customers and prospects under NDA.
Where does my data physically live?
In dedicated storage inside an Azure subscription created for your engagement, in your geography, encrypted at rest with AES-256 and readable only by test compute running inside that subscription. Storage is not shared with any other customer and no copy is made outside Microsoft Azure.
What does destroyed at completion mean in practice?
The Azure subscription and tenant that held the engagement are deleted under ELTON's formal retention and disposal procedure, which the SOC 2 auditor tested without exception. Azure's envelope encryption means the data encryption keys can only be unwrapped by a key encryption key held in Key Vault, so decommissioned storage is cryptographically unreadable, and Microsoft sanitizes physical media under NIST SP 800-88 with cryptographic erasure and secure overwrite.
What does ELTON keep after a test?
The record: findings, test cases, ratings, evidence and dispositions, because FDA traceability depends on it. The raw inputs you provided, such as documentation, source and firmware images, are not part of that record and are destroyed with the engagement subscription.
Who are your subprocessors?
Microsoft only: Microsoft Azure for the platform and the internal testing infrastructure, and Microsoft 365 E5 for identity, email, documents and device management. Azure is the single subservice organization in ELTON's SOC 2 report and its SOC 2 is reviewed annually. There is no outsourced development, no contractor with data access, and no AI provider that receives customer data.
Do you support customer-managed keys and single sign-on?
Yes to both. Per-customer encryption keys can be held in Azure Key Vault or an HSM under your control, with annual rotation and Key Vault access logging. Authentication is through Microsoft Entra ID, which federates with your identity provider over SAML 2.0, OIDC or ADFS, and MFA is enforced for every user regardless of role.
Does customer data ever reach OpenAI or Anthropic?
No. ELTON uses frontier model APIs to help engineers write the code of the testing harness, and the inputs to that work are ELTON's own code, specifications and tests. Customer data is processed only by open-weight models hosted on ELTON compute inside the tenant, with no vendor account, no telemetry and no outbound model calls.
If AI is probabilistic, how is the output FDA-defensible?
Because the decisions FDA reads are not made by AI. Ratings come from the qualified MDDT CVSS rubric, exploitability verdicts come with the test case that proves them, and dispositions carry a written rationale. AI is used where a defensible decision is not required, such as drafting text or proposing candidate paths for verification, and every AI-assisted output is reviewed by a person before it reaches you.