Secure by design.
The engine runs inside your own pod. The data path stays yours, every byte SHA-256 verified, with no third-party runtime dependencies.
Elara-Cortex · security & procurement
Prepared for security and procurement review prior to purchase.
The information your security and procurement teams typically request to evaluate Elara Route: where it runs, how your data is handled, and how we meet your requirements. Short, plain, and clear about what we have today and what is on the roadmap.
Where it runs
| Deployment options | Private cloud (your VPC), on-premise (a container in your data centre), or our managed cloud. Air-gapped delivery is available for defence and sovereign work. |
|---|---|
| Your data stays yours | The routing engine receives only the problem instance you send (stops, vehicles, a matrix), never your demand model, your pricing, or your customer records. On-premise, nothing leaves your tenancy. |
| No training on your data | We do not use your requests to train any model. There is no model. The engine is solved mathematics, not a guess; the same input returns the same answer, every time. |
How your data is handled
| API keys at rest | Hashed with a peppered SHA-256, we never store the raw key. A leaked database does not expose a working key. |
|---|---|
| Offline route packets | The downloadable route pack is encrypted and licence-bound (authenticated encryption); it only opens for the licensed device. |
| In transit | HTTPS only, HSTS with a one-year max-age and subdomains. TLS is enforced at the edge. |
| Logs | We do not log raw request bodies or secrets. Telemetry is per-key counts, not your payloads. |
| Deletion | Account and key deletion on request; see the privacy policy. POPIA data-subject rights are honoured. |
Application security
The application is hardened, and the answer is checked.
The controls a security review asks about, stated plainly. Each control is implemented in the request path rather than added as an external layer.
Every field is checked first.
Every field is parsed, finiteness- and range-checked before any compute. Malformed, non-finite or negative input is rejected with a typed 4xx, never a silent wrong answer.
Hardened on every response.
Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a scoped Permissions-Policy on every response.
No request can monopolise.
Per-key rate limiting; budgets are clamped to the plan ceiling so a single request cannot monopolise the service.
You re-check, you never trust.
Every solver answer ships a certificate, coverage, capacity and a recomputed cost, that your own engineers re-check with arithmetic. The answer is solved, not guessed, so you never have to trust a black box.
Compliance & commercials
| Privacy law | Aligned to POPIA (South Africa) and structured for GDPR with a data-processing addendum for business customers, see Legal §7. |
|---|---|
| Service levels | Paid plans target 99.9% monthly availability with service credits; Enterprise terms are set in your contract, see Legal §SLA. |
| Company | Elara-Cortex Mathematical Infrastructure for Complex Systems. A board-governed company: Elara-Cortex Mathematical Infrastructure for Complex Systems, Inc. (a Delaware C-Corporation), Jersey City, New Jersey; and Elara-Cortex Mathematical Infrastructure for Complex Systems (Pty) Ltd, Johannesburg (CIPC Enterprise Number 2026/492586/07). Operations in New Jersey and Johannesburg. |
Start the review
Send your security questionnaire to security@elara-cortex.com and we will return it completed, with the DPA and an on-premise deployment guide. To evaluate before procurement, a free 14-day key runs your own data through the engine, no procurement needed.

