How Elumen protects your data

Elumen analyzes organizational communication under consulting engagements. Here's how we earn your trust.

What happens to the communications Elumen analyzes?

Identity is separated from content before anything reaches us: a staging step on the consulting side pseudonymizes names — in message text and metadata — and the name-to-pseudonym mapping never leaves the consulting team.

Our instrument is never given names, so it cannot produce findings about named employees — architecture, not policy.

Everything is engagement-scoped: the corpus and all derived analysis are deleted or returned when the engagement ends, with deletion attested in writing.

Can findings identify individual employees?

Findings are reported at the group level only, with a minimum group size (default: no group smaller than 5).

No analysis of a named, non-consenting employee is ever persisted or reported.

Any employee can be excluded from ingestion on request; access, correction, and deletion requests route through your organization as data controller.

Is this a surveillance tool?

No. Elumen maps how an organization communicates — patterns across groups — to inform a consulting engagement's diagnosis. The organization is what gets diagnosed; individual employees are not monitored, evaluated, or scored.

Individual-level evaluation is structurally unavailable, not just disallowed: findings exist at the group level, and the instrument never receives the identity information it would need to assess a named person.

Engagement terms bind processing to the engagement's diagnostic purpose — no re-identification attempts, no use beyond the engagement.

Who processes the data?

Analysis uses AI (Anthropic's Claude API) under commercial terms that prohibit training on customer content; inputs and outputs are retained transiently (currently up to 30 days), then deleted.

We use Supabase for authentication and data storage, with Row Level Security on all tables and encryption at rest.

The full list of subprocessors — roles, regions, and safeguards — is published in the Subprocessors section below, and is updated before any new subprocessor touches engagement data.

We do not sell your data, use it for advertising, or train models on it — ours or anyone's.

What about compliance?

Elumen is designed to be deployable in regulated environments.

Text-only analysis (not biometric) — compatible with EU AI Act Art. 3(39).

Group-level reporting with a minimum group size is designed with works-council and co-determination contexts in mind.

Subprocessors

Elumen uses the following subprocessors to deliver the engagement service. Engagement corpora reach Elumen only after consultant-side pseudonymization; no subprocessor below receives client-held identity mappings.

Anthropic (US)

Role: Model inference

Data touched: Pseudonymized corpus content and derived analysis, transiently

Safeguards: Commercial terms: no training on customer content; transient retention (currently up to 30 days), then deletion

Railway (US — us-west, California)

Role: Backend application hosting

Data touched: Pseudonymized engagement data in processing; operational logs

Safeguards: Access-controlled infrastructure; engagement-scoped deletion

Vercel (US — iad1, Washington D.C.)

Role: Frontend hosting and request proxy

Data touched: Session and request metadata

Safeguards: Access-controlled; no corpus persistence at this layer

Supabase (US — us-west-2, Oregon)

Role: Managed database

Data touched: Pseudonymized engagement state and analysis records

Safeguards: Encrypted at rest; row-level security; engagement-scoped deletion

Upstash (US — us-west-1, N. California)

Role: Managed cache

Data touched: Transient analysis-output cache entries

Safeguards: TTL-bounded; flushed at engagement close

This list is updated before any new subprocessor touches engagement data. Questions: allan@elumen.ai.

Still have questions? privacy@elumen.ai