Security at Calethia

We help companies achieve compliance, so we take our own security seriously. Here's how we protect your data.

Security Features

The controls we run to protect your compliance data.

Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3.

Access Control

Role-based access control (RBAC) ensures users only see what they need.

Audit Logging

Every action is logged with immutable audit trails for accountability.

Infrastructure Security

Hosted on Google Cloud Platform with SOC 2 certified infrastructure.

Data Isolation

Customer data is logically isolated with strict tenant boundaries.

Compliance

We follow SOC 2 controls and industry best practices today, and will pursue formal certification when the time is right.

Security Practices

What we do, by area.

Application Security

  • Secure software development lifecycle (SSDLC)
  • Dependency vulnerability scanning
  • Code review requirements

Data Protection

  • No customer data used for training
  • Data retention policies
  • Right to deletion (GDPR/CCPA)

Access & Operations

  • SSO/SAML support
  • Multi-factor authentication
  • Least privilege access
  • 24/7 infrastructure monitoring
  • Incident response procedures

Built by Security Engineers

  • Built and reviewed by security engineers, not just compliance staff
  • We know what auditors and pentesters look for, because we've sat on that side of the table
  • Security is reviewed on every change, not bolted on before an audit

Our Compliance Journey

We're an early-stage company. We'll pursue formal certifications, including SOC 2 Type II, GDPR, and CCPA, when the time is right for our size and stage.

SOC 2 Type II

Planned

GDPR

Planned

CCPA

Planned

In the meantime, we follow SOC 2 controls and industry best practices day to day, and we're glad to complete vendor security assessments or questionnaires so you can evaluate us now.

Self-Hosted & On-Prem

Self-hosted deployment into your own AWS or GCP account is in progress. If you need this sooner, reach out and we'll work with you directly.

Have security questions?

Happy to answer questions or send over documentation.