Security Policy
Our Security Commitment
CALACC takes security seriously. We employ industry-leading practices to protect your data and maintain the integrity of our platform.
Encryption
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.
Access Control
We implement role-based access control (RBAC) and principle of least privilege to ensure users only have access to data they need.
Compliance
CALACC is compliant with:
- SOC 2 Type II
- PDPA (Personal Data Protection Act)
- ISO 27001
- GDPR (where applicable)
Security Audits
We conduct regular security audits and penetration testing to identify and address vulnerabilities.
Incident Response
In the event of a security incident, we follow a comprehensive incident response plan to minimize impact and keep our users informed.
Reporting Security Issues
If you discover a security vulnerability, please email security@calacc.com with details. We appreciate responsible disclosure and will work with you to resolve the issue.