Agents get a door, never a spare key
Your upstream credentials never leave Elva. Every tool call is identified, scoped, redacted, throttled, and logged. This page is written for the person who has to sign off on that.
Five checks, in order, fail closed
Nothing reaches your API until identity, scope, redaction, rate, and audit have all passed. A failure at any step denies the call and records why. There is no bypass path and no unscoped mode.
What we store, and what we never see
Elva reads your code to derive specs; it does not need your production data. Request and response bodies are not retained by default, and PII fields are redacted at the gateway before they reach an agent.
Compliance, and how we work toward it
We would rather tell you our real status than imply a badge we do not hold. Ask us for the current pack and we will send it with dates attached.
Revoke in seconds, explain in minutes
One click kills a key, an agent, or a whole server, and the log keeps everything it did up to that moment. That is the difference between an incident and an unanswerable question.
FAQ
How does Elva secure agent calls?
Five ordered checks on every tool call: identity (OAuth2 token or managed key resolved to a named agent), tool scope, field redaction per contract, rate and quota, and an audit record.
Does Elva expose my API credentials to agents?
No. Upstream credentials stay in the gateway. Agents hold scoped keys that can be limited per tool and revoked instantly, one key per consumer.
What ends up in the audit log?
Every call records the actor, the tool, an arguments hash, latency, and the outcome, queryable per key and per tool.
How do I report a security issue?
Email security@theneo.io. Reports get a response within one business day.
Send this page to your security team
They will ask about scopes, logs, residency, and revocation. All of it is answered here.
