Security and Data Handling
How Elly stores, protects, and gives you control over your workspace's data.
Where your data lives#
Elly runs on AWS, with primary storage in the US. Everything associated with your workspace — jobs, candidates, resumes, meeting recordings, transcripts — is stored encrypted at rest. Network traffic between you and Elly uses TLS.
Meeting recordings and transcripts are stored in AWS S3; candidate profiles and pipeline data in a managed relational database; search indexes and background queues in AWS-native services.
Who can see your data#
- Your team — Everyone in your workspace can see all of the workspace's candidates, jobs, and meetings. Access control is workspace-wide, not per-record. If you need finer-grained access, contact support.
- Candidates you interview — Candidates only see what you explicitly send them (interview invitations, outreach emails, shared meeting links).
- Elly staff — Production access is limited to on-call engineers and is audit-logged. We don't access workspace data except to diagnose issues you've reported.
- Sub-processors — A small number of third-party services process data on our behalf: Recall (video recording), Twilio (phone calls), Vapi (AI voice interviews), Stripe (billing), OpenAI / Anthropic (AI summaries and interview questions). Each is bound by a data processing agreement.
Compliance#
Elly maintains standard SaaS compliance posture. For up-to-date SOC 2, GDPR, and DPA details — including our current list of sub-processors — contact support (see below).
Data export#
You can export:
- Candidates — As CSV from the Candidates list; see Candidates. Use filters to scope the export.
- Meetings — Transcript and summary for an individual meeting can be downloaded from the meeting detail page.
- Campaign activity — Per-campaign performance and send logs are exportable from the campaign detail page.
If you need a full workspace export (everything, machine-readable), contact support.
Data deletion#
- Candidates — Deletable individually or in bulk from the Candidates list. Deletion is immediate and permanent.
- Meetings — Deletable from the meeting detail page. Recordings and transcripts are removed from storage on deletion.
- Jobs — Closing a job keeps its history. Deleting a job removes it and its candidates are detached from the pipeline (not deleted from the workspace).
- Workspace — To delete an entire workspace and all associated data, contact support. We'll confirm via email and process the deletion within the standard SLA.
GDPR and CCPA deletion requests on behalf of candidates are honored — contact support with the request and the candidate's identifying email.
Authentication#
Elly supports Google OAuth, Microsoft Entra ID, and email + password sign-in (password-based auth uses AWS Cognito under the hood). Two-factor authentication is enforced via your identity provider — enable it in Google or Microsoft to protect your Elly account.
Session management#
Sessions expire after a period of inactivity. Owners can force-terminate another member's sessions from the Team settings page if a device is lost.
Security incidents#
If you believe you've discovered a security issue, email support@elly.ai. For urgent concerns affecting your workspace, use the support email below for the fastest response.
Contact#
For data export requests, deletion requests, or compliance documentation, email support@elly.ai.
Last updated