Skip to main content

Legal & Compliance

Elestio is SOC 2 Type 2, ISO 27001, HIPAA, and GDPR compliant. Every service runs on a dedicated instance with encrypted storage, automated security patches, and 24/7 monitoring.

For the full picture, see the Security & Compliance page.

Certifications and compliance​

Compliance is verified through continuous third-party evaluation.

  • SOC 2 Type 2 — AICPA auditing standard for security, availability, and confidentiality controls.
  • ISO 27001 — International standard for Information Security Management Systems.
  • GDPR — EU and EEA regulation for data protection and privacy.
  • HIPAA — U.S. regulation for the privacy and security of health data.

Security at every layer​

  • Dedicated hardware — Every service runs on a dedicated VM with kernel-level security.
  • End-to-end encryption — Connections between your computer, the dashboard, and your services are encrypted with TLS.
  • Network safeguards — Firewalls with IP whitelisting, plus Bring Your Own VM (BYOVM) and Bring Your Own Account (BYOA) for extra control.
  • Backups — External S3-compatible backups for efficient recovery, plus local backups for flexibility.
  • Yearly security audits — External evaluations every year, with an internal Security Operations team continuously strengthening defenses.
  • Automated updates — Software and system updates applied regularly, without manual intervention.

Questions?​

For anything about compliance, privacy, or security: