Skip to content

Site search

Type to search Pages

Trust & security

What runs today, stated plainly for the person signing off.

Elidian is pre-launch. This page sets out where data lives, who processes it, what is automated, and — where a control does not yet exist — says so and names what does.

What runs today

The controls that run behind this site.

The site you are reading, the records it keeps, and the providers that touch them — described as they actually run, not as a roadmap.

A database for Elidian alone

Records are kept in a Neon Postgres database provisioned for this venture, not a shared multi-tenant store. The site is hosted on Netlify, and traffic between your browser and the service is encrypted in transit.

Five named sub-processors

Personal data is handled by Netlify, Neon, Resend, Plausible Analytics and Cloudflare — and no others. Each receives only what its function requires, and the full list is published rather than available on request.

Consent enforced by category

Cookie consent is set per category. Usage measurement is cookieless and identifies nobody; no advertising or cross-site tracking cookies are placed on your device.

Abuse screening without profiling

Public forms are protected by Cloudflare Turnstile, which distinguishes a person from a bot without profiling the visitor or building a behavioural record.

One codebase across applications

The mobile and desktop applications are built from the same code and the same rules as this website and talk to the same authenticated endpoints, so no channel carries a weaker posture than another.

Built to WCAG 2.1 AA

The interface follows WCAG 2.1 AA: semantic structure, full keyboard operability, visible focus, focus-trapped dialogs that restore focus, and honoured reduced-motion settings. No independent audit has been commissioned.

Honest absences

What we do not claim.

A security reviewer is looking for specifics. Where a buyer would expect something we do not have, we name the gap and what exists instead.

No certification or audit

Elidian holds no SOC 2, ISO 27001 or comparable attestation, and no independent security audit or penetration test has been commissioned. We say so rather than imply a badge we have not earned.

No availability guarantee

There is no service-level agreement or uptime figure on the record today. The site is hosted on Netlify and served over an encrypted connection; we would rather not publish a number we cannot stand behind.

No bug-bounty programme

We do not pay for disclosure. There is a published vulnerability disclosure policy setting out scope and good-faith research, and a named person owns the response.

No signed-in product yet

Because Elidian renders no authenticated application today, there are no user accounts, roles or an internal audit trail on this site to describe. We will not claim controls before they exist.

What runs today, and what we do not yet have.

Elidian is pre-launch. This page describes what actually runs today — the website you are reading and the records behind it — not a product roadmap. Where a security review would expect a control we have not yet built, we name the gap and describe what exists in its place, because for a reviewer an honest absence is worth more than a vague assurance.

Where data lives

The site is served by Netlify. The records it keeps are held in a Neon Postgres database provisioned for Elidian alone, rather than a shared multi-tenant store, and traffic between your browser and the service is encrypted while it travels. Personal data is handled by five named providers and no others: Netlify serves and delivers the site; Neon hosts the database; Resend delivers transactional email; Plausible Analytics measures usage without cookies; and Cloudflare Turnstile screens public forms for automated abuse. That list is published in full rather than shared on request, and our Privacy Policy sets out what each provider receives.

What a visitor can and cannot do

There is no signed-in product surface here yet. Because the site renders no authenticated application today, there are no accounts, roles or an internal audit trail to bound — a claim we would rather not make prematurely. What you can do is read these pages, follow a public link, or submit a form; every public form is screened by Cloudflare Turnstile, which separates a person from a bot without profiling the visitor. The mobile and desktop applications, when they run, are built from the same code and the same rules as the website and speak to the same authenticated endpoints, so no channel carries a weaker posture than another.

What is automated, and where a person decides

In the product Elidian is building, AI colleagues perform the operating work — verifying listings, matching capabilities and flagging standing that has lapsed — while named human governors set eligibility rules, approve who is onboarded and answer for the outcomes. Ambiguous or high-stakes cases are referred to a person rather than cleared automatically. On this website today, no such decisions are made about you; the only automated step is the anti-abuse check on public forms.

What a security review actually asks.

Ask a security question, or request your data.

A named person owns the response. To report a vulnerability, request data-processing terms, or ask what we hold about you, write to us.