Security
Last updated: June 2, 2026
Our Commitment to Security
At Calper, security is fundamental to everything we do. We implement industry-standard security measures to protect your data, maintain privacy, and ensure the integrity of our Service.
Infrastructure Security
Cloud Infrastructure
- Enterprise Cloud Platform: Industry-leading cloud infrastructure with managed databases
- Secure Application Hosting: Professional hosting with automatic encryption
- Geographic Redundancy: Data replicated across multiple regions
- DDoS Protection: Built-in protection against distributed denial-of-service attacks
Network Security
- Transport Encryption: All data in transit is encrypted using industry-standard protocols
- Secure Protocols: Modern, secure communication protocols only
- Certificate Management: Automated certificate rotation and renewal
Data Security
Encryption
- At Rest: All data encrypted in secure database systems
- In Transit: Industry-standard encryption for all network communications
- Sensitive Data: Additional encryption layer for payment and personal information
Access Controls
- Database Security Rules: Row-level security ensuring users only access their own data
- Server-Side Operations: Strict access controls on backend operations
- Principle of Least Privilege: Users and systems have minimum necessary permissions
- Role-Based Access: Different permission levels for different user types
Data Isolation
- User data segregated by workspace and user ID
- Multi-tenant architecture with strict isolation
- No cross-contamination between user accounts
Authentication & Authorization
- Industry-Standard Authentication: Secure authentication via trusted identity providers
- No Password Storage: We never store or handle passwords directly
- Session Management: Secure, encrypted session tokens with automatic expiration
- Modern Authentication Libraries: Industry-standard authentication implementation
- CSRF Protection: Built-in protection against cross-site request forgery
Payment Security
- PCI Compliance: Payment processing handled by PCI-DSS compliant processors
- No Card Storage: We never store payment card details
- Tokenization: Sensitive payment data tokenized by payment processor
- Secure Webhooks: Webhook signature verification for payment events
Application Security
Development Practices
- Type Safety: Strongly-typed code for improved security
- Input Validation: All user inputs validated and sanitized
- Injection Prevention: Protection against common injection attacks
- XSS Protection: Content Security Policy and framework-level protections
- Security Headers: Industry-standard security headers implemented
Code Security
- Dependency Scanning: Regular security audits of dependencies
- Automated Updates: Security patches applied promptly
- Code Reviews: Security-focused code review process
Monitoring & Incident Response
Monitoring
- Real-time Monitoring: 24/7 system monitoring and alerting
- Error Tracking: Automated error detection and reporting
- Audit Logs: Comprehensive logging of security-relevant events
- Anomaly Detection: Automated detection of unusual patterns
Incident Response
- Response Plan: Documented incident response procedures
- Rapid Response: Quick identification and mitigation of security issues
- User Notification: Transparent communication about security incidents
- Post-Incident Review: Analysis and improvement after incidents
Third-Party Security
We carefully vet all third-party services for security and compliance:
- Cloud Infrastructure: SOC 2, ISO 27001, GDPR compliant providers
- Payment Processing: PCI-DSS Level 1 certified payment processors
- Email Delivery: Secure email delivery with authentication protocols
- Application Hosting: SOC 2 Type II certified hosting platforms
Compliance
- GDPR: European Union data protection compliance
- Data Privacy: Adherence to privacy regulations
- Right to Deletion: User data deletion upon request
- Data Portability: Export your data at any time
User Security Best Practices
Help keep your account secure:
- Use a strong account password with two-factor authentication enabled
- Don't share your account credentials
- Log out on shared devices
- Review connected applications and integrations regularly
- Report suspicious activity immediately
- Keep your browser and operating system updated
Responsible Disclosure
We welcome security researchers to report vulnerabilities:
- Report security issues through our support channels
- Provide detailed information about the vulnerability
- Allow reasonable time for us to respond and fix
- We appreciate responsible disclosure
Contact Security Team
For security concerns or to report vulnerabilities, please contact us through the Service support channels with "Security" in the subject line.
Continuous Improvement
Security is an ongoing process. We continuously review and improve our security measures, stay current with security best practices, and adapt to emerging threats to keep your data safe.