Elysium provides AI-powered document extraction and analysis for commercial real estate. Leases, loan documents, and guaranties are sensitive, so we encrypt all customer data, keep each customer's data isolated, and never use customer documents to train AI models.
Data encryption
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Our infrastructure runs on a small set of established cloud providers, listed under Subprocessors below.
- All customer data is stored in the United States.
Tenant isolation
- Each customer's documents and extracted data are logically isolated, with no cross-tenant data access.
- Access is scoped by account, so users only see their own organization's data.
AI and model usage
- Customer documents are never used to train or fine-tune models.
- We're intentionally provider-agnostic and use leading LLM vendors (Anthropic and Google Gemini) for extraction. That avoids dependence on a single vendor and lets us route around outages or model issues at any one provider.
- Enterprise API terms apply with each vendor, so your data isn't used for their model training either.
Personal information (PII)
CRE documents can contain personal information, such as names and contact details of tenants, guarantors, or borrowers, guarantor financial details, and signatures.
- PII gets the same encryption and access controls as all other customer data.
- PII is not used to train or fine-tune any AI models.
- PII is processed only as far as needed to deliver extraction and analysis. It is never sold, shared, or used for any secondary purpose.
- Access to documents containing PII is limited to authorized Elysium personnel and the AI subprocessors used for extraction.
Data retention and deletion
- While your account is active, we keep your data as long as it's needed to deliver the service. Nothing is deleted automatically.
- After an account is offboarded, data is kept for up to 12 months to support final analysis or transition needs, then removed from active systems.
- You can ask us to delete your data, including PII, at any time, and we'll honor that request promptly.
Access control
- Internal Elysium team members get role-based access control.
- Single sign-on (SSO) support is on our near-term roadmap.
- Audit logging of document access is on our near-term roadmap.
Incident response
- We detect incidents through application monitoring and alerting, vendor notifications, and customer reports. Every suspected incident is escalated immediately for triage.
- Our process is to contain the issue, assess its scope, fix the cause, notify affected customers, and review what happened to prevent a repeat.
- If we confirm an incident affecting your data, we'll notify you within 72 hours. The notice explains what happened, what data was involved, what we've done to contain it, and what you should do, if anything.
- Incidents that start at a subprocessor follow the same assessment and notification timeline.
Compliance status
Elysium is not currently SOC 2 certified. We follow SOC 2-aligned practices for encryption, access control, and vendor management, and we're prepared to pursue formal certification as customer needs require.
Subprocessors
| Vendor | Category |
|---|---|
| Render | Infrastructure |
| Vercel | Infrastructure |
| Supabase | Infrastructure |
| Google Cloud Platform | Infrastructure |
| AWS | Infrastructure |
| Azure | Infrastructure |
| Anthropic | AI processing |
| Google Gemini | AI processing |
Frequently asked questions
Does Elysium use my documents to train AI models?
No. Customer documents are never used to train or fine-tune models, and our AI vendors (Anthropic and Google Gemini) process data under enterprise API terms that exclude model training.
Is Elysium SOC 2 certified?
Not yet. Elysium follows SOC 2-aligned practices for encryption, access control, and vendor management, and is prepared to pursue formal certification as customer needs require.
How is my data encrypted?
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
Where is my data stored?
All customer data is stored in the United States.
Can other customers see my data?
No. Each customer's documents and extracted data are logically isolated, and access is scoped to your own organization.
How long does Elysium keep my data?
For as long as your account is active. After offboarding, data is kept for up to 12 months, then removed from active systems. You can ask for deletion at any time.
What happens if there's a security incident?
We contain and investigate it, and notify affected customers within 72 hours of confirming an incident that affects their data.
Questions or security reviews
For a deeper security review, a Data Processing Agreement (DPA), or to report a suspected security issue, contact joe@elysium-cre.com.