Compliance
Certifications, compliance and legal credentials
This page records ELECTE’s certifications, compliance posture and legal credentials in the detail a security or procurement review asks for. It is maintained alongside the answers given in security questionnaires; where the two differ, the questionnaire is authoritative.
Certifications & standards
Audit in progress
SOC 2 Type I
Attested with Lowerplane. Design of controls at a point in time.
Audit in progress
SOC 2 Type II
Not yet attested. The audit assessing operating effectiveness over a period is underway.
Compliant
GDPR
Data Processing Agreement available to every customer; sub-processors listed in the DPA.
In place
EU data residency
All production data hosted in EU regions. No transfer outside the EEA.
Member
W3C
Member organisation.
Data protection
- Residency
- All production data is hosted in EU regions and is not transferred outside the EEA. Sub-processors are listed in the DPA.
- Data Processing Agreement
- A DPA is available to every enterprise customer.
- Data-subject rights
- Honored end to end. Deletion on request, verified.
- Retention
- Daily backups, retained for 90 days.
Security practices
Encryption
- AES-256 at rest, TLS 1.3 in transit
- Keys managed in a dedicated KMS
- Automatic key rotation
Residency
- All production data hosted in EU regions
- No transfer outside the EEA
- Sub-processors listed in the DPA - on request
Privacy
- DPA available to every enterprise customer
- Data-subject rights honored end to end
- Deletion on request, verified
Access control
- SSO via SAML 2.0 and OIDC
- MFA mandatory for all accounts
- Granular roles with full audit logs
Monitoring
- Weekly vulnerability scans
- Annual third-party penetration tests
- 99.9% uptime SLA
Incident response
- Notification within 72 hours
- 24/7 response team
- Daily backups, 90-day retention
Documents & evidence
- Security Whitepaper Architecture, encryption, sub-processors and incident response in full.
- Data Processing AgreementProvided to every enterprise customer.On request
- Sub-processor listMaintained as an annex to the DPA.On request
- SOC 2 Type II reportDoes not exist yet — the audit is in progress.Available under NDA on completion of the audit
Need the detail your security team asks for?
The Security Whitepaper covers architecture, encryption, sub-processors, and incident response in full.