Security Policy

Our Security Commitment

CALACC takes security seriously. We employ industry-leading practices to protect your data and maintain the integrity of our platform.

Encryption

All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.

Access Control

We implement role-based access control (RBAC) and principle of least privilege to ensure users only have access to data they need.

Compliance

CALACC is compliant with:

  • SOC 2 Type II
  • PDPA (Personal Data Protection Act)
  • ISO 27001
  • GDPR (where applicable)

Security Audits

We conduct regular security audits and penetration testing to identify and address vulnerabilities.

Incident Response

In the event of a security incident, we follow a comprehensive incident response plan to minimize impact and keep our users informed.

Reporting Security Issues

If you discover a security vulnerability, please email security@calacc.com with details. We appreciate responsible disclosure and will work with you to resolve the issue.