generated: '2026-09-06' method: searched source: https://www.elsevier.com/security provider: Elsevier providerId: elsevier name: Elsevier Security & Compliance url: https://www.elsevier.com/security http_status: 200 description: >- Elsevier publishes a corporate security and compliance page covering encryption in transit, vulnerability scanning, secure code review, bug bounties, AI data handling and privacy posture. It is a narrative page, not a document portal: no certificate, report, bridge letter or subprocessor list is downloadable from it. certifications: - name: ISO/IEC 27001 status: claimed artifact_available: false evidence: >- "We maintain compliance with leading security frameworks and hold certifications such as ISO 27001." — https://www.elsevier.com/security programs: - name: Bug bounty status: claimed public_program: false evidence: >- "We use industry best practices such as web application firewalls, application and infrastructure vulnerability scanning, secure code reviews, bug bounties, and other preventive, detective, and response controls." note: >- No program is listed on HackerOne (404) or Bugcrowd (404) under an elsevier handle, and no scope, reward table or submission address is published. Probed 2026-09-06. privacy: regimes: - GDPR - CCPA policy: https://www.elsevier.com/legal/privacy-policy data_protection_officer: true ai_posture: evidence: >- "Our architecture and associated contracts preclude third-party model providers from logging or training" on customer inputs — https://www.elsevier.com/security tdm_reservation: >- Separately and machine-readably, Elsevier reserves text-and-data-mining rights over its own content via /.well-known/tdmrep.json and per-response tdm-reservation headers. See well-known/elsevier-well-known.yml. gaps: - name: trust portal detail: https://trust.elsevier.com resolves but returns HTTP 403 to an ordinary browser request (probed 2026-09-06). - name: SOC 2 detail: Not claimed and not published. - name: vulnerability disclosure policy detail: >- No public VDP, no security.txt on any Elsevier host, and no reporting address. Elsevier says it runs bug bounties but publishes no way for a finder to reach it. See security/elsevier-domain-security.yml for the transport-layer probe.