Security & Data

What we ship.

Honest controls that are live today across elastictree.com and Elastic Tree Studio — not a compliance brochure.

In production

Live controls

Aligned with our internal security checklist — SSO, signed bridges, TLS, headers, payment verification, and privacy notices.

Studio SSO

Sign in once with Google, Microsoft, LinkedIn, or email on elastictree.com. The same account unlocks TScribe, QualView, Ethos Pulse, AI Gaze, and DataWiz when SSO is enabled.

Signed studio handoff

After login, studios receive a short-lived bridge code. Consume requires an HMAC signature; return URLs are allowlisted so codes are not sent to arbitrary hosts.

Encryption in transit

HTTPS / TLS on the corporate site and Studio deployments (Vercel and Railway).

Browser security headers

Content-Security-Policy, HSTS, and related headers on the website and Next.js studios (QualView allows camera/mic where needed for live rooms).

Verified payments

PayU response hashes are verified before plans unlock. Studio fulfill calls require a matching billing signature.

Privacy basics

Cookie consent banner, published Privacy Policy and Terms, and soft-hidden account / studio hub routes that stay out of search indexes.

Roadmap

Not claimed as shipped

We do not market these as standard product features yet. Talk to us if a programme needs them.

Next step

Security questionnaire or DPA?

Send your checklist — we will map each control to what is live on the website and each Studio, without overclaiming.

Contact us