Procurement-ready trust center
This page is structured for vendor-management review and due-diligence questionnaires, with each control labeled as a current control or a roadmap item.
Elizian is built for large, regulated institutions. This Trust Center is structured for procurement and security due diligence; every control is clearly labeled as a current control or a roadmap item.
Contact security teamLast reviewed
2026-09-09
Controls are presented as Current control or Roadmap. Roadmap items are not represented as currently achieved.
35
Current controls
0
Roadmap items
Elizian is built for large, regulated institutions. This Trust Center supports procurement and security due diligence by distinguishing controls Elizian operates today from capabilities on our roadmap. Roadmap items are not represented as currently achieved.
This page is structured for vendor-management review and due-diligence questionnaires, with each control labeled as a current control or a roadmap item.
Encryption in transit and at rest, network segmentation, and least-privilege access principles across the platform.
Action ownership, approvals, configuration controls, and auditability govern how the platform is operated.
Foundamental security controls protecting Elizian and the operational data it processes.
Data is encrypted during transmission and while stored.
Segmented network architecture limits lateral movement between components.
Access is granted on a least-privilege basis by default.
How operational information is handled, retained, and scoped to the appropriate boundaries.
Retention of operational information is configurable to client requirements.
Information is exchanged through structured, governed channels.
Data boundaries respect the regulatory and organizational structure of each healthcare system.
Tenant separation, scoping, and governed configuration of operational data.
Each client operates within a separated tenant boundary with isolated data, configurations, and operational context.
Terminology and operating rules respect the regulatory structure of each healthcare system.
Approval workflows and configuration controls provide operational accountability.
Authentication and authorization controls governing who can reach and act on operational data.
SSO is available across every workspace.
MFA is available across access paths.
Granular RBAC scoped by role, team, tenant, and country.
Users see and act only on what they are accountable for.
Time-stamped, attributable records of actions, approvals, and configuration changes.
Audit history covers actions, approvals, escalations, and configuration changes.
Activity is attributable to users and roles.
Resilience, recovery, and incident response for mission-critical operations.
Resilient infrastructure supports continuous availability for mission-critical operations.
Documented recovery procedures support restoration of service.
Defined detection, escalation, and communication processes support timely resolution and notification.
How required enterprise systems connect through agreed interfaces and scoped information flows. Specific systems and data scope are defined during discovery and confirmed with the client's technical and security teams.
Required enterprise systems connect through agreed interfaces and access.
Information flows are scoped and confirmed with the client's technical and security teams.
Responsible, human-in-control AI assistance with clear boundaries on decision authority.
AI assists operational teams; it does not replace licensed or accountable decision-makers.
Clinical judgment, authorization decisions, and regulated responsibilities remain with the appropriate licensed or accountable organization.
Hospitals, physicians, health plans and appropriately licensed organizations retain clinical decisions, discharge approval, medical-necessity determinations, authorization decisions and patient-care responsibility. Elizian provides operational workflow, coordination, execution visibility, escalation and completion tracking around those decisions; not licensed clinical judgment. Elizian does not diagnose, determine treatment, or determine medical necessity.
Elizian does not diagnose, determine treatment, or determine medical necessity.
Regulated responsibilities remain with licensed or accountable organizations and professionals.
Elizian coordinates execution; it does not replace the clinical workforce.
Governance of provider information, capacity, and qualification through configurable workflows.
Provider information, capacity, and qualification are governed through configurable workflows.
Provider-related actions are attributable and auditable.
Controls designed to support client obligations. Specific certifications are listed only when verified and approved; none are currently claimed here.
Controls are designed to help clients meet their regulatory and contractual obligations. Elizian does not claim specific certifications unless verified and approved.
Operating rules respect the regulatory structure of each healthcare system.
Requesting security documentation, vendor-management questionnaires, and due-diligence materials.
Security documentation is available to qualified prospects under appropriate confidentiality.
Due-diligence questionnaires are supported through the security team.
Elizian's current design and development target is WCAG 2.2 Level AA, supported by semantic structure, keyboard navigation, and reduced-motion practices.
Read the Accessibility StatementAppropriate enterprise buyers may request additional due-diligence materials subject to applicable confidentiality controls. The categories below are request pathways; not a library of prepared downloads. Availability of any specific document is confirmed through the request process and not all materials may currently be prepared.
High-level summary of Elizian's security model and control posture.
RequestPlatform architecture and data-flow patterns relevant to security review.
RequestIdentity, authentication, and role-based access controls.
RequestDetection, escalation, and notification processes.
RequestResilience and recovery approach for mission-critical operations.
RequestHow operational information is handled, retained, and scoped.
RequestResponsible-AI boundaries and the human-in-control operating model.
RequestCategories of subprocessors involved in service delivery, subject to engagement scope.
RequestBusiness Associate Agreement availability and terms, subject to qualification and execution.
RequestDirect contact for vendor-management questionnaires and due-diligence requests.
RequestReady to request security documentation?
Submit a request and our security team will confirm available materials and applicable confidentiality requirements.