Your portal credentials are the most sensitive thing you entrust to Elementar. This page explains exactly how they are protected — and includes a due-diligence answer sheet for your security and compliance teams. If you need something this page doesn't cover, email eilon@elementarai.com directly.

Encrypted under a key that is yours alone

Each client's portal credentials are encrypted with a key derived uniquely for that client (PBKDF2-HMAC-SHA256 over a master key, with a per-tenant salt). One client's key cannot decrypt another client's data — not even inside Elementar's own systems.

Keys held in a dedicated key vault

The master encryption key lives in Azure Key Vault and is retrieved at runtime only by an authorized managed identity. It is never stored in Elementar's application, environment, containers, or source code.

Authenticated encryption, never plaintext

Credentials are stored using authenticated encryption — Fernet (AES-128-CBC with HMAC-SHA256), which is tamper-evident. They are never written in plaintext. Documents and the database are additionally encrypted at rest with AES-256 on Microsoft Azure.

Least-privilege access, fully audited

Access to secrets follows least privilege — scoped per secret, not blanket — and every access to the key vault is logged to an audit trail.

Read-only access, MFA-protected login

Elementar connects to your portals read-only — no funds can ever move — and handles two-factor authentication automatically. Your Elementar login is protected by MFA, server-side session revocation, and brute-force throttling.

Your right to erasure

Deleting your account removes your entire database — including every stored credential — immediately. Disconnecting a single portal deactivates its credential immediately; the stored secret is then purged in a follow-up cleanup. Elementar operates under Swiss nFADP and EU GDPR.

Continuous dependency patching

Our software dependencies are continuously scanned for known vulnerabilities. High-severity fixes are applied promptly and validated by an automated test suite on a staging environment before reaching production.

European data residency, per-tenant isolation

All data is processed and stored exclusively in European Azure regions (EU and Switzerland). Elementar GmbH is Swiss-domiciled. Each client is a separate tenant with its own database and its own encryption key — no commingling between clients.

Due-diligence answer sheet

The table below is written for a security or compliance reviewer working through a vendor-assessment checklist. Every row reflects the controls described on this page.

Question Answer
Credential storage at rest Recoverable third-party portal credentials, encrypted with Fernet (AES-128-CBC + HMAC-SHA256) under per-tenant derived keys (PBKDF2-HMAC-SHA256, per-tenant salt). Credentials must be replayed into portals, so they are encrypted (not hash-only) — and never stored in plaintext.
Key management Master key held in Azure Key Vault (Standard SKU, software-protected). Fetched at runtime via Azure managed identity; never in application config, environment variables, containers, or source. Per-tenant keys are derived in memory and not stored. An HSM-backed envelope is on the roadmap.
Can Elementar staff read credentials? Credentials are decrypted only by automated processes, to perform the portal logins you authorize. A client-initiated credential reveal exists and is audited. Operational/break-glass access is restricted to least privilege and logged.
Encryption in transit TLS 1.2 or higher.
Data residency Processed and stored exclusively in EU and Switzerland Azure regions. Elementar GmbH is Swiss-domiciled, under nFADP and GDPR.
Tenant isolation Per-tenant databases and per-tenant encryption keys. No cross-tenant decryption is possible.
Access control & audit Least-privilege RBAC on the key vault, scoped per secret. Key Vault access is logged with retention.
Authentication MFA on client logins, server-side token revocation, brute-force rate-limiting, modern signed tokens, and a CI secret-scanning gate that blocks secrets from entering the codebase.
Portal access scope Read-only. No transactional capability — funds can never move. Two-factor authentication is handled automatically.
Credential lifecycle / erasure Deleting your account removes your entire database — including every stored credential — immediately. Disconnecting a single portal deactivates its credential immediately; the stored secret is then purged in a follow-up cleanup.
Certifications Elementar is not currently SOC 2 or ISO 27001 certified.
Incident response & DR Documented credential-compromise and master-key break-glass / disaster-recovery runbooks.
Network controls Key Vault access is gated by Entra ID and RBAC. A private-network lock is on the roadmap.
Key rotation Rotation capability is in place; a formal rotation cadence is being established.
Dependency patching GitHub Dependabot monitors the dependency graph for known CVEs; high-severity alerts are remediated promptly and gated by automated tests on the preview deploy before reaching production.

Your rights and how to reach us

Questions about how your data is handled go to a person, not a form. Email eilon@elementarai.com directly — it reaches the team behind Elementar.

Frequently asked questions

Can Elementar staff read my portal credentials?

Credentials are decrypted only by automated processes, to perform the portal logins you authorize. A client-initiated credential reveal exists and is audited. Operational/break-glass access is restricted to least privilege and logged.

Where are my credentials and data stored?

Processed and stored exclusively in EU and Switzerland Azure regions. Elementar GmbH is Swiss-domiciled, under nFADP and GDPR. Each client has a separate database and a separate encryption key — no cross-tenant decryption is possible.

What happens to my credentials when I offboard?

Deleting your account removes your entire database — including every stored credential — immediately. Disconnecting a single portal deactivates its credential immediately; the stored secret is then purged in a follow-up cleanup.

Is Elementar SOC 2 or ISO 27001 certified?

Elementar is not currently SOC 2 or ISO 27001 certified.

Reach a person directly

If your security or compliance team has a follow-up question this page doesn't answer, email us directly and we'll take it from there.

Email eilon@elementarai.com

Also: How we work · Troubleshooting · Academy home