Security, governance, and responsible operations.

Elizian is built for large, regulated institutions. This Trust Center is structured for procurement and security due diligence; every control is clearly labeled as a current control or a roadmap item.

Contact security team

Overview

Elizian is built for large, regulated institutions. This Trust Center supports procurement and security due diligence by distinguishing controls Elizian operates today from capabilities on our roadmap. Roadmap items are not represented as currently achieved.

Current control

Procurement-ready trust center

This page is structured for vendor-management review and due-diligence questionnaires, with each control labeled as a current control or a roadmap item.

Current control

Layered security model

Encryption in transit and at rest, network segmentation, and least-privilege access principles across the platform.

Current control

Operational accountability

Action ownership, approvals, configuration controls, and auditability govern how the platform is operated.

Security

Foundamental security controls protecting Elizian and the operational data it processes.

Current control

Encryption in transit and at rest

Data is encrypted during transmission and while stored.

Current control

Network segmentation

Segmented network architecture limits lateral movement between components.

Current control

Least-privilege by default

Access is granted on a least-privilege basis by default.

Privacy

How operational information is handled, retained, and scoped to the appropriate boundaries.

Current control

Configurable retention

Retention of operational information is configurable to client requirements.

Current control

Structured data exchange

Information is exchanged through structured, governed channels.

Current control

Regional and organizational scoping

Data boundaries respect the regulatory and organizational structure of each healthcare system.

Data Governance

Tenant separation, scoping, and governed configuration of operational data.

Current control

Tenant separation

Each client operates within a separated tenant boundary with isolated data, configurations, and operational context.

Current control

Country and regional scoping

Terminology and operating rules respect the regulatory structure of each healthcare system.

Current control

Configurable governance and approvals

Approval workflows and configuration controls provide operational accountability.

Identity & Access

Authentication and authorization controls governing who can reach and act on operational data.

Current control

Single sign-on

SSO is available across every workspace.

Current control

Multi-factor authentication

MFA is available across access paths.

Current control

Role-based access control

Granular RBAC scoped by role, team, tenant, and country.

Current control

Permissions scoping

Users see and act only on what they are accountable for.

Auditability

Time-stamped, attributable records of actions, approvals, and configuration changes.

Current control

Time-stamped activity logs

Audit history covers actions, approvals, escalations, and configuration changes.

Current control

Attributable accountability

Activity is attributable to users and roles.

Business Continuity

Resilience, recovery, and incident response for mission-critical operations.

Current control

Resilient infrastructure

Resilient infrastructure supports continuous availability for mission-critical operations.

Current control

Recovery procedures

Documented recovery procedures support restoration of service.

Current control

Incident response

Defined detection, escalation, and communication processes support timely resolution and notification.

Integration Security

How required enterprise systems connect through agreed interfaces and scoped information flows. Specific systems and data scope are defined during discovery and confirmed with the client's technical and security teams.

Current control

Structured system integration

Required enterprise systems connect through agreed interfaces and access.

Current control

Scoped information flows

Information flows are scoped and confirmed with the client's technical and security teams.

AI Governance

Responsible, human-in-control AI assistance with clear boundaries on decision authority.

Current control

Human-in-control AI assistance

AI assists operational teams; it does not replace licensed or accountable decision-makers.

Current control

Responsible AI boundaries

Clinical judgment, authorization decisions, and regulated responsibilities remain with the appropriate licensed or accountable organization.

Elizian executes workflows. Healthcare organizations retain clinical authority.

Hospitals, physicians, health plans and appropriately licensed organizations retain clinical decisions, discharge approval, medical-necessity determinations, authorization decisions and patient-care responsibility. Elizian provides operational workflow, coordination, execution visibility, escalation and completion tracking around those decisions; not licensed clinical judgment. Elizian does not diagnose, determine treatment, or determine medical necessity.

Current control

No clinical decision-making

Elizian does not diagnose, determine treatment, or determine medical necessity.

Current control

Licensed-professional responsibility

Regulated responsibilities remain with licensed or accountable organizations and professionals.

Current control

Operational, not clinical, role

Elizian coordinates execution; it does not replace the clinical workforce.

Provider Governance

Governance of provider information, capacity, and qualification through configurable workflows.

Current control

Provider data and capacity governance

Provider information, capacity, and qualification are governed through configurable workflows.

Current control

Attributable provider actions

Provider-related actions are attributable and auditable.

Compliance

Controls designed to support client obligations. Specific certifications are listed only when verified and approved; none are currently claimed here.

Current control

Supports client obligations

Controls are designed to help clients meet their regulatory and contractual obligations. Elizian does not claim specific certifications unless verified and approved.

Current control

Regional regulatory scoping

Operating rules respect the regulatory structure of each healthcare system.

Security Documents

Requesting security documentation, vendor-management questionnaires, and due-diligence materials.

Current control

Security documentation on request

Security documentation is available to qualified prospects under appropriate confidentiality.

Current control

Vendor-management questionnaires

Due-diligence questionnaires are supported through the security team.

Current control

Accessibility statement

Elizian's current design and development target is WCAG 2.2 Level AA, supported by semantic structure, keyboard navigation, and reduced-motion practices.

Read the Accessibility Statement

Enterprise Security Documentation

Appropriate enterprise buyers may request additional due-diligence materials subject to applicable confidentiality controls. The categories below are request pathways; not a library of prepared downloads. Availability of any specific document is confirmed through the request process and not all materials may currently be prepared.

Security Overview

High-level summary of Elizian's security model and control posture.

Request

Architecture / Data Flow Overview

Platform architecture and data-flow patterns relevant to security review.

Request

Access Control Overview

Identity, authentication, and role-based access controls.

Request

Incident Response Summary

Detection, escalation, and notification processes.

Request

Business Continuity Summary

Resilience and recovery approach for mission-critical operations.

Request

Privacy / Data Processing Information

How operational information is handled, retained, and scoped.

Request

AI Governance Summary

Responsible-AI boundaries and the human-in-control operating model.

Request

Subprocessor Information

Categories of subprocessors involved in service delivery, subject to engagement scope.

Request

BAA Information

Business Associate Agreement availability and terms, subject to qualification and execution.

Request

Security Questionnaire Contact

Direct contact for vendor-management questionnaires and due-diligence requests.

Request

Ready to request security documentation?

Submit a request and our security team will confirm available materials and applicable confidentiality requirements.

Request Security Documentation