Security
Security is part of the system.
How we protect your business's information: the controls we use, the practices we follow, and the part you play.
Contents
Security model
Each business's information is kept separate. ELMNT uses tenant-level access controls and row-level security where supported, with sign-in required across ELMNT ONE, the Customer Portal, our internal team tools, and connected websites. Server-side authorization and ownership checks protect each business's data; hiding something in the interface is never treated as security on its own.
People only see the tools and information their role allows. Server-side permissions are enforced in addition to interface-level controls, and privileged support and administrative actions are limited to approved roles and are designed to leave an audit record.
Data protection
Your information is protected on its way to and from ELMNT, and card details are handled by dedicated payment providers. Supported production traffic uses HTTPS. Authentication secrets, service credentials, and payment details are kept out of public client bundles, and card payments are processed by approved payment providers rather than stored as full card data by ELMNT.
Files are stored privately and shared through protected links. Where protected delivery is required, files use private storage and time-limited access paths, and upload controls block executable and unsafe file types.
Availability and recovery
We show you real status, not guesses. Monitoring, backup, SSL, domain, deployment, and recovery information comes from live provider data when available; when a provider has not confirmed something, ELMNT shows it as unknown or pending rather than assuming.
What is included depends on your plan. Backup frequency, retention, recovery objectives, and uptime commitments depend on your active hosting plan and written order.
Desktop applications
Our desktop apps are locked down to protect your session. The ELMNT ONE desktop app and the app used by the ELMNT team isolate product sessions, disable Node.js access in remote pages, restrict navigation to approved origins, deny unapproved permissions, and require an explicit choice before screen sharing.
Installers are only released after they are verified. Public installers are released only after platform signing and, on macOS, notarization and Gatekeeper verification.
Customer responsibilities
Security is shared, and a few habits on your side keep your account safe. Protect your account with a unique password, turn on multi-factor authentication where available, review who on your team has access, remove departed team members promptly, and keep your recovery information current.
Report suspicious activity quickly. Never send a password, private key, authentication code, or full card number in a support request.
Responsible disclosure
If you find a security problem, tell us privately and we will take it seriously. Send a concise description, the affected URL or component, steps to reproduce it, and the potential impact. Do not access data that is not yours, disrupt production, use social engineering, or publish an unresolved issue.
ELMNT will acknowledge credible reports, investigate them, and coordinate a fix and disclosure based on severity.
Report a vulnerability privately
Email security@elmntone.com with reproduction steps and no unnecessary customer data.