Security &compliance.
Your data is protected with enterprise-grade security measures and industry-leading compliance standards. The details below are the specifics, not the marketing.
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your messages and customer data are always protected.
Infrastructure security
Hosted on Google Cloud Platform with multi-tenant isolation, automatic backups, and a 99.9% uptime SLA in secure, redundant data centres.
Access controls
Role-based access control, mandatory multi-factor authentication, and comprehensive audit logs track every access to your data.
Compliance
GDPR compliant, CCPA ready, SOC 2 Type II in progress. We follow industry best practice and maintain strict data-governance policies.
Certifications & standards
SOC 2 Type II: currently in audit process.
ISO 27001: information security management system on the roadmap.
GDPR & CCPA: fully compliant with data protection regulations. A Data Processing Agreement is available. See Data Processing.
Data encryption
In transit: TLS 1.3 with perfect forward secrecy for all API communications and web traffic.
At rest: AES-256 encryption for all stored data including messages, attachments, and customer information.
Key management: Google Cloud KMS with automatic key rotation and hardware security module (HSM) backing.
Application security
Penetration testing: annual third-party penetration tests to identify and remediate vulnerabilities.
Vulnerability scanning: automated daily scans of infrastructure and dependencies.
Security patches: critical patches applied within 48 hours, regular patches within 7 days.
Secure development: code reviews, static analysis, and dependency scanning integrated into CI/CD.
Incident response
We maintain 24/7 security monitoring and an incident response team. In the event of a security incident:
- Immediate containment and investigation
- Customer notification within 48 hours for data breaches
- Root cause analysis and remediation
- Post-incident review and preventive measures
- Regulatory notification as required by law
Business continuity
Backups: automated daily backups with 30-day retention and point-in-time recovery.
Disaster recovery: multi-region redundancy with an RTO of 4 hours and RPO of 1 hour.
Availability: 99.9% uptime SLA with automatic failover and load balancing.
Privacy by design
Data minimisation, purpose limitation, and user consent are core principles. Customers keep full control of their data with self-service export and deletion.
Third-party security
All sub-processors undergo security assessments and sign data processing agreements. Current sub-processors: Google Cloud Platform, MongoDB Atlas, Twilio, SendGrid, Meta WhatsApp Business API.
Security questions?
For security enquiries, vulnerability reports, or to request our security documentation, contact security@caviusconnect.com.
