Security & reliability
Designed to be trusted with the operation — and honest about what isn’t claimed.
Security and reliability are considered from the start rather than bolted on later. This page describes what we actually do, and states plainly the certifications and guarantees we do not hold.
How systems are designed
Six things every Elion system is built around.
These are architectural decisions made during the design phase, which is the only point at which they are cheap to make.
Role-based access
Access and permissions are defined per role, per branch and per responsibility, and are part of the design rather than a later configuration pass.
Traceable workflows
Actions and approvals leave a clear, reviewable trail — which is what makes a multi-stage approval chain worth having at all.
Human approval where it matters
Sensitive actions keep a person in the loop by design. Automation prepares the action; a person authorises it.
Backups & recovery
Backup and recovery are planned as part of each implementation, with the restore path defined rather than assumed.
Controlled releases
Changes are tested and rolled out in a controlled, monitored way, so a release is a planned event rather than a risk.
Least-connection integration
A connected system is given the narrowest access that does the job — read-only wherever writing is not genuinely required.
Traceability, in practice
An approval chain is only meaningful if you can see it.
Every purchase requisition in this running deployment sits in whichever of the eight approval stages it has actually reached — the trail is the interface, not a hidden log.

Every purchase requisition on one board, in whichever of the eight approval stages it has actually reached.
Real production data. Account-holder chip redacted before publication.
Defined per engagement
Security requirements are decided per implementation, not declared here.
A generic security page cannot tell you where your data will live or who will hold admin access. Those answers are specific to your operation, and they get written down as part of the engagement.
- Where data is hosted, and under whose account and control.
- Who holds administrative access, and how that access is reviewed.
- Backup frequency, retention, and the tested procedure for restoring.
- Which integrations may write to which systems, and which are read-only.
- How long operational records are kept, and what happens at the end of the engagement.
- What is logged, who can read those logs, and for how long they are held.
Where AI reads a document or a camera feed, the review step that keeps a person in control is described on Technology & Integrations.
What we do not claim
The absences, stated as plainly as the capabilities.
A security page that only lists strengths is not a security page. These are the things Elion does not have, written here so nobody has to discover them later.
- We do not hold ISO 27001, SOC 2, PCI DSS or any other formal security certification, and we do not claim one.
- We do not publish an uptime guarantee or an SLA percentage on this website — availability commitments belong in a signed agreement, tied to a specific system and hosting arrangement.
- We are not a named or certified partner of any platform vendor, and no logo on this site should be read as an endorsement.
- We do not claim penetration-test results, audit reports or compliance attestations that have not been performed.
If any of these changes — a certification is obtained, an audit is completed — it will be named here with the issuing body and the date, and not before.
This website
How this site itself is built.
The site you are reading is a static marketing site. It is worth being specific about it, because it is the one Elion system you can inspect yourself right now.
- This website sets no cookies and contains no analytics, advertising or session-recording code.
- Both typefaces are served from this domain, so a page load contacts no third-party host.
- Pages are served over HTTPS with HSTS, a strict Content-Security-Policy, X-Content-Type-Options, a restrictive Permissions-Policy, and framing denied.
- No customer, employee or business data is embedded in the site, and no secret or API key is exposed to the browser.
- Every product screenshot has been privacy-reviewed before publication, with the specific redactions stated in the disclosure beneath it.
The full detail on storage and tracking is on the Cookies page, and on what happens to an enquiry in the Privacy notice.
The next step
Start with a Systems Assessment.
A focused conversation about how your operation runs today, where it loses time, and what a connected system would change. No obligation to build anything.
In an assessment we
- Understand how your operation runs today
- Identify the disconnected systems and bottlenecks
- Map the highest-value improvements
- Decide together whether Elion is the right fit
