Skip to content
Prelaunch information

ElseHour policies and trust

Security

The current prelaunch security posture and the controls ElseHour is designed to require before public accounts open.

Updated July 13, 2026 Version: prelaunch-2026-07-13 Not an effective app policy

Current status

ElseHour is not yet a deployed public application. This page distinguishes controls implemented in source from production controls that still require hosting, configuration, operational proof, and owner approval. It is not a claim of certification.

Security principles

  • Collect the smallest input needed for the present decision.
  • Keep source account, portfolio, identity, time zone, authority, and projection scope explicit.
  • Use row-level ownership enforcement and backend-only privileged credentials.
  • Encrypt sensitive source material in transit and at rest and purge it on a short independent expiry path.
  • Keep models outside canonical state and external authority.
  • Require recent authentication for export and deletion.
  • Keep ordinary logs and telemetry content-free.

Before public release

The project still requires production evidence for:

  • vendor ownership, regions, access roles, MFA, recovery, and subprocessors;
  • hosted authentication denial, revocation, abuse controls, and operator procedures;
  • backups, restoration, deletion, source expiry, alerts, and incident response;
  • signed-device acceptance, accessibility, store review, and release operations;
  • an approved security-reporting contact and staffed response process.

Responsible disclosure

No professional security contact or public vulnerability-reporting program has been established. A reporting channel, acknowledgement target, scope, and any safe-harbor or bounty terms will be published before live accounts open. Do not send secrets, credentials, or another person’s information through the disabled waitlist field.

Claims not made

ElseHour does not currently claim SOC 2, ISO 27001, HIPAA, GDPR, CCPA, “bank-grade” security, end-to-end encryption, Zero Data Retention, a public SLA, 24/7 monitoring, or guaranteed prevention of breaches.