Elva · Trust Center

Elva Trust Center

Trust center

Elva maintains a public trust center documenting SOC 2 Type II, ISO 27001, and ISO 27701 compliance.

API ManagementMCP ServerMCP LogsMCP InsightsAPI ClientAPI ContractAPI GovernanceAPI DiscoveryOpenAPIAPI TestingDeveloper ToolsAI Agent Infrastructure
Trust center:

Certifications & Compliance

SOC 2 Type IIISO 27001ISO 27701

Source

Trust Center

elva-trust-center.yml Raw ↑
generated: '2026-09-07'
method: searched
source: https://getelva.ai/security
name: Elva security page (Theneo-held certifications)
note: >-
  Elva publishes a dedicated security page rather than a hosted trust-center portal.
  It states plainly that Elva is a product of Theneo and that the certifications,
  security contact, and DPA are issued to Theneo, covering the infrastructure Elva
  runs on. Security pack (reports, certificates, pen-test summary) available on
  request via hello@getelva.ai, under NDA.
certifications:
  - name: SOC 2 Type II
    status: certified
    holder: Theneo
    detail: report under NDA
  - name: ISO 27001
    status: certified
    holder: Theneo
    detail: certificates on request
  - name: ISO 27701
    status: certified
    holder: Theneo
    detail: privacy management, certificates on request
programs:
  - name: GDPR
    status: compliant
    detail: DPA available, EU data residency on request
  - name: Penetration testing
    status: annual
    detail: third-party, summary shared under NDA
controls:
  - Encryption TLS 1.3 in transit, AES-256 at rest, per-tenant isolation
  - SSO / SAML and SCIM on Enterprise plans
  - Configurable data residency (regional hosting, private cloud, on-prem)
  - Five ordered checks on every MCP tool call (identity, scope, redaction, rate, audit), fail closed
  - Request/response bodies not retained by default; PII redacted at the gateway
  - Instant revocation of keys, agents, and servers; full audit log export (JSON, CSV, webhook)
evidence:
  - url: https://getelva.ai/security
    http_status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elva-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.