Full practices
Last updated August 30, 2026. Responsible disclosure: [email protected].
Security is foundational to Caedral's infrastructure. This page describes how we protect the Service, your data, and API access. It provides a high-level overview of our practices and is not a contractual commitment unless expressly incorporated into a signed agreement with Caedral.
Security inquiries: [email protected].
Infrastructure
- Production systems run on hardened cloud infrastructure with network segmentation between environments
- Production access is restricted to authorized personnel, granted on a least-privilege basis, and logged
- Infrastructure changes follow peer review and controlled deployment procedures
- Development, staging, and production environments are logically separated
Encryption
- All API and dashboard traffic is encrypted in transit using TLS 1.2 or higher
- Data at rest is encrypted using industry-standard algorithms on cloud provider infrastructure
- API keys are stored using one-way hashing; full secret keys are displayed only once at creation
- Secrets and credentials are managed through dedicated secrets management tooling, not source code
Authentication and access control
- All API requests require a valid bearer token tied to your account
- Dashboard sessions use secure, HTTP-only cookies with appropriate expiration
- Team and role-based access controls are available on eligible plans
- API keys can be rotated without service interruption by creating a new key before revoking the old one
- We monitor for anomalous authentication patterns and may suspend keys that appear compromised
Application security
- Code changes undergo review before deployment to production
- Dependencies are monitored for known vulnerabilities
- Input validation and rate limiting are enforced at the API layer
- We conduct periodic security assessments of critical systems
Monitoring and incident response
We monitor the Service continuously for anomalies, abuse, and security events. Our incident response process includes detection, containment, investigation, remediation, and post-incident review.
| Severity | Description | Customer notification |
|---|---|---|
| Critical | Confirmed breach of customer data or API keys | Within 72 hours of confirmation, where required by law |
| High | Service compromise affecting availability or integrity | Status update within 24 hours via email or dashboard |
| Medium | Security event contained without customer data impact | Notification if customer action is required |
| Low | Minor issue with no customer impact | No notification unless relevant to your account |
If you believe your account or API keys have been compromised, rotate your keys immediately and contact [email protected].
Payment security
Payment processing is handled entirely by Stripe, Inc., a PCI DSS Level 1 certified payment processor. Caedral does not store, process, or transmit complete payment card numbers on our systems. Billing data received from Stripe is handled according to our Privacy Policy.
Vulnerability disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in the Service, report it to [email protected]. Include a description, steps to reproduce, and potential impact. You may also report through our Discord community for initial triage, but email is preferred for sensitive reports.
Safe harbor
If you make a good-faith effort to comply with this policy — including allowing reasonable time for us to investigate and remediate before public disclosure — Caedral will not initiate legal action against you for security research conducted in accordance with these guidelines. Do not access data belonging to other users, disrupt the Service, or engage in social engineering against Caedral personnel or users.
Out of scope
- Denial-of-service attacks against production infrastructure
- Physical security testing of Caedral facilities or personnel
- Social engineering or phishing against employees or users
- Issues in third-party services not operated by Caedral
- Findings from automated scanners without demonstrated impact
Data processing and enterprise
Enterprise customers may request a Data Processing Agreement (DPA), security questionnaire completion, or subprocessor list by contacting [email protected]. We respond to reasonable security assessments within 15 business days.
Compliance posture
Caedral designs security practices with common industry frameworks in mind, including SOC 2 trust principles and NIST guidance. We have not yet completed a formal SOC 2 audit. As the platform matures, we intend to pursue independent security certifications and will update this page when achieved.
We do not currently hold formal HIPAA, PCI DSS (direct), FedRAMP, or ISO 27001 certifications. Customers with specific compliance requirements should contact [email protected] before deploying regulated workloads.