Security engineered into every line of code.

Your calendar schedules, client intake submissions, and confidential voice calls are protected with bank-grade encryption and tenant isolation.

AES-256 & TLS 1.3 Encryption

All client data, scheduling history, and intake records are encrypted at rest using industry-standard AES-256 and transmitted exclusively over TLS 1.3.

OAuth 2.0 Token Vaulting

Google, Microsoft, and Apple calendar credentials are never stored in raw plaintext. Tokens are isolated in secure cryptographic vaults with automated token rotation.

Strict Multi-Tenant Isolation

Data boundaries between organizations are strictly enforced at the database and application layers, preventing any cross-tenant data leakage.

Zero Public AI Training

We strictly enforce a zero-retention policy with our foundation voice model providers. Your meeting audio and transcripts are never used to train public AI models.

Compliance & Regulatory Standards

GDPR Compliant

Active

Full European General Data Protection Regulation compliance with DPA support and right-to-be-forgotten controls.

CCPA / CPRA

Active

California Consumer Privacy Act compliant with full user transparency and data export rights.

HIPAA Readiness

Ready

Business Associate Agreements (BAA) available for qualified enterprise healthcare and telehealth plans.

SOC 2 Type II

Aligned

Engineered in strict alignment with AICPA Trust Services Criteria for security, availability, and confidentiality.

Responsible Vulnerability Disclosure

We welcome security researchers to test and review our perimeter responsibly. If you discover a potential vulnerability, please email our security response team directly at security@calendeur.com. We acknowledge receipt within 24 hours and do not pursue legal action against ethical researchers following responsible disclosure.

Have questions about security?

Our infrastructure and security teams are available to complete vendor assessment questionnaires.