Your Elevator Business Data. Enterprise-Grade Protection.

ElevatorPlus runs on Amazon AWS - the same infrastructure trusted by the world's largest enterprises. With 100+ role-based access controls and a complete audit trail on every action, your data is protected at every level.

Amazon AWS

Enterprise Infrastructure

100+ Access Controls

No Data Leaks

Full Audit Trail

On Every Action

ElevatorPlus Data Security

NDA and DPA Signed as Standard

A Non-Disclosure Agreement and Data Processing Agreement are signed as standard with every ElevatorPlus contract. Your business data is not used for any purpose beyond operating the platform for you. These are not optional add-ons or enterprise extras - they are in place from day one. More about who builds ElevatorPlus.

Where Your Data Lives

ElevatorPlus runs on enterprise cloud infrastructure, hosted in the region your business operates in. For Indian customers, that is Mumbai. For customers elsewhere, the server sits in or near their own country.

We are not locked to a single cloud provider. Amazon Web Services is the default, and where a market or a customer requires a different provider, we deploy there instead.

Cloud Infrastructure Standard

The default deployment for every ElevatorPlus account

Storage Amazon S3
Hosting Amazon AWS
Backups Daily automated
Uptime 99.9% SLA
Updates Auto-pushed
Security AES-256 at rest, encrypted in transit
Region Matched to your country. Mumbai for India.

Self-Hosted Deployment

For Regulated Markets

For countries with data-residency or sovereignty regulations, ElevatorPlus can be deployed on your own infrastructure - keeping data fully within your borders.

  • Data stays inside your jurisdiction
  • Maintained & updated by the ElevatorPlus team
  • Eligibility & customization vary by country
Check eligibility for your country

What Goes Into Keeping Your Elevator Business Data Safe

Modern Technology Stack

NestJS, React, Flutter, and Amazon AWS. 2020s frameworks, not the legacy stacks older elevator software runs on. Fewer vulnerabilities, faster patches.

Access Control (100+ Roles)

Every user has a role. Every role defines exactly which modules, screens, and actions they can access. Nothing crosses over.

Audit Trail

Every action is logged with user identity, device, timestamp, and old/new values. Complete record for audits, insurance claims, or disputes.

Data Encryption

Data at rest is encrypted using AES-256. Data is encrypted in transit. API communications are secured via HTTPS with token-based authentication.

Role-Based API Access

External integrations use scoped API keys. Each integration accesses only the data it needs, nothing more. See all integrations.

Your Records Ready When the Inspector Arrives

Inspection scheduling

Annual inspection scheduling and record-keeping per elevator

Digital certificate storage

Digital certificate storage - accessible from any device

Service history

Full service history per lift - searchable, exportable

Compliance record structure

ASME A17.1 / CSA B44 / ISO 25745 compliance record structure

QR code scan

QR code on every elevator → scan → full service and compliance history in seconds

Audit-ready reports

Audit-ready reports: technician who performed service, timestamp, checklist completed, photos attached

Compliance and Controls

In-Country Data Hosting

For markets where local regulations require data to remain within national borders, ElevatorPlus provides a self-hosted deployment option. This is configured during onboarding, maintained by the ElevatorPlus team, and reviewed in line with the compliance requirements of each country we operate in.

ISO 27001 and SOC 2 - Target: Q1 2027

ElevatorPlus is targeting ISO 27001 and SOC 2 Type II certification by Q1 2027. These are targets on our internal roadmap, not current certifications. We are documenting controls, running internal audits, and preparing for formal assessment. We will publish the outcomes when the process is complete.

Access and Account Controls

Account security sits at the user level as well as the infrastructure level. See access control for the full role configuration.

  • Two-factor authentication - available for all accounts, enforced where required.
  • 100+ role-based access controls - every user sees only what their role permits.
  • Visible device login activity - account holders can see which devices are signed in.
  • Remote and forced logout - sessions terminated automatically when an account is disabled.

The same controls apply in the field app.

Vendor Independence

Accucia Softwares builds software and does nothing else. We do not install elevators, service them, or sell elevator components. We never compete with our customers for maintenance contracts. The people who use ElevatorPlus are the same people we are trying to help run their businesses - there is no conflict of interest in how we store or use their data.

Tested on Every Release, Not Once a Year

Most software is penetration tested annually, if at all. Twelve months is a long time to run on the assumption that nothing has changed.

ElevatorPlus runs vulnerability scanning and penetration testing on every release. We ship at least twelve releases a year, so the platform is tested at least twelve times a year, and each test covers code that has just changed rather than code that changed eleven months ago.

India's Data Protection Act, and What It Actually Requires Today

India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 are being brought into force in stages. The Rules were published in the Gazette on 14 November 2025. The substantive obligations on Data Fiduciaries commence eighteen months from that date, in mid-2027.

Which means nobody in India is DPDP compliant today, because the duties that compliance would be measured against are not yet in force. Any vendor telling you otherwise is describing something that does not exist.

What we can tell you is what we have built. Rule 6 of the DPDP Rules sets out the minimum security safeguards a Data Fiduciary will owe, and ElevatorPlus already meets them: encryption of personal data, controls on access to systems, logging and monitoring so unauthorised access can be detected and investigated, backups so processing continues if data is compromised, log retention, and contractual security obligations on every processor we engage.

One point worth knowing, because it is widely misstated: the DPDP Act does not require personal data to be stored in India. We host in-region because it is better practice and because it suits customers who want it, not because the Act compels it.

Where your data lives

Common Questions on ElevatorPlus Data Security

Q

Where is my ElevatorPlus data stored?

Your data is hosted in the region your business operates in. For Indian customers that is Mumbai. Amazon Web Services is our default provider, with daily automated backups and a 99.9% uptime SLA, and we are not restricted to a single provider where a market requires otherwise.

Q

Can I host ElevatorPlus on my own server?

Self-hosted deployment is available for specific countries with data residency regulatory requirements. It comes with additional customization charges and is maintained by the ElevatorPlus team. Contact us to check eligibility for your country.

Q

What happens to my data if I stop using ElevatorPlus?

We provide a full data export in structured format before account closure.

Q

Who in my company can access sensitive financial data?

You control this entirely through the 100+ role-based access control system. Set permissions per module, per screen, per action type.

Q

Is ElevatorPlus GDPR compliant?

ElevatorPlus supports GDPR-aligned data practices including data export, audit trails, and access control. For EU deployments, contact us to discuss your specific data residency requirements.

Have Specific Security or Compliance Requirements?

Operating in a regulated market or have specific data governance requirements? We'll walk through exactly how ElevatorPlus handles your situation.

Request Security Briefing