Security at Calethia
We help companies achieve compliance, so we take our own security seriously. Here's how we protect your data.
Security Features
Enterprise-grade security controls to protect your compliance data.
All data is encrypted at rest using AES-256 and in transit using TLS 1.3.
Role-based access control (RBAC) ensures users only see what they need.
Every action is logged with immutable audit trails for accountability.
Hosted on Google Cloud Platform with SOC 2 certified infrastructure.
Customer data is logically isolated with strict tenant boundaries.
We follow SOC 2 controls and best practices as we work toward certification.
Security Practices
Our comprehensive security program covers all aspects of our operations.
Application Security
- Secure software development lifecycle (SSDLC)
- Regular penetration testing
- Dependency vulnerability scanning
- Code review requirements
Data Protection
- No customer data used for training
- Data retention policies
- Right to deletion (GDPR/CCPA)
- Encrypted backups
Operational Security
- 24/7 infrastructure monitoring
- Incident response procedures
- Disaster recovery planning
- Regular security training
Access Management
- SSO/SAML support
- Multi-factor authentication
- Least privilege access
- Regular access reviews
Our Compliance Journey
We practice what we preach. As an early-stage company, we're actively working toward the same compliance standards we help our customers achieve.
SOC 2 Type II
In Progress
GDPR
In Progress
CCPA
In Progress
We follow industry best practices and SOC 2 controls today while working toward formal certification.
Have security questions?
Our security team is happy to answer questions or provide additional documentation.