Security at Calethia
We help companies achieve compliance, so we take our own security seriously. Here's how we protect your data.
Security Features
The controls we run to protect your compliance data.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3.
Role-based access control (RBAC) ensures users only see what they need.
Every action is logged with immutable audit trails for accountability.
Hosted on Google Cloud Platform with SOC 2 certified infrastructure.
Customer data is logically isolated with strict tenant boundaries.
We follow SOC 2 controls and industry best practices today, and will pursue formal certification when the time is right.
Security Practices
What we do, by area.
Application Security
- Secure software development lifecycle (SSDLC)
- Dependency vulnerability scanning
- Code review requirements
Data Protection
- No customer data used for training
- Data retention policies
- Right to deletion (GDPR/CCPA)
Access & Operations
- SSO/SAML support
- Multi-factor authentication
- Least privilege access
- 24/7 infrastructure monitoring
- Incident response procedures
Built by Security Engineers
- Built and reviewed by security engineers, not just compliance staff
- We know what auditors and pentesters look for, because we've sat on that side of the table
- Security is reviewed on every change, not bolted on before an audit
Our Compliance Journey
We're an early-stage company. We'll pursue formal certifications, including SOC 2 Type II, GDPR, and CCPA, when the time is right for our size and stage.
SOC 2 Type II
Planned
GDPR
Planned
CCPA
Planned
In the meantime, we follow SOC 2 controls and industry best practices day to day, and we're glad to complete vendor security assessments or questionnaires so you can evaluate us now.
Self-Hosted & On-Prem
Self-hosted deployment into your own AWS or GCP account is in progress. If you need this sooner, reach out and we'll work with you directly.