ECL Platform

Security & Trust

Last updated May 2026 · Version 2.1

Security questions? Contact us at security@eclplatform.io for our latest penetration-test summary and SOC 2 status.

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are independently encrypted. Encryption keys are managed using a dedicated key management service with automatic annual rotation. No customer data is stored in plaintext at any layer of the stack.

Data Residency

By default, all customer data is stored within the primary region selected at account creation. Enterprise customers can request custom data residency arrangements including single-region isolation and on-premise deployment options. Currency and timezone settings are locked after initial setup to comply with IFRS 9 audit requirements.

Authentication

All user sessions are protected by signed, short-lived JWT tokens with automatic refresh. Password requirements enforce a minimum of 12 characters with complexity rules. Multi-factor authentication (TOTP) is available for all plans and mandatory for Admin and Reviewer roles on the Growth and Enterprise tiers. SSO via SAML 2.0 is available on Enterprise.

Audit Trail

Every ECL run produces an immutable, cryptographically hashed record stored for a minimum of 7 years — the IFRS 9 mandated retention period. Hash verification allows external auditors to confirm that exported results match the original computation without accessing the platform. All user actions (file uploads, parameter changes, user management) are logged with timestamps and actor identifiers.

Backups

Database backups are performed hourly with 30-day point-in-time recovery. Backups are stored in a geographically separate region from primary data. Recovery time objective (RTO) is 4 hours; recovery point objective (RPO) is 1 hour. Backup restoration is tested quarterly.

Compliance

ECL Platform is designed for IFRS 9 compliance. Our SOC 2 Type II assessment is in progress. Contact us for our latest penetration test executive summary and current compliance status. We are aligned with OWASP Top 10 mitigations and conduct annual third-party security reviews.

Incident Response

We maintain a documented incident response plan with defined severity levels and escalation paths. Customers affected by a security incident will be notified within 72 hours of detection, consistent with GDPR Article 33 obligations. A post-incident report is provided for all Severity 1 and Severity 2 events.

Sub-processors

We use a limited number of carefully vetted sub-processors for infrastructure and operational purposes. All sub-processors are contractually bound to our data protection standards. The current list of sub-processors is available on request and updated when changes are made. Customers on Enterprise plans receive advance notice of sub-processor changes.