Skip to content

Trust

Security

How Caedral protects infrastructure, data, and API access. We have not completed a SOC 2 audit and do not claim HIPAA, FedRAMP, or ISO 27001. Stripe is PCI DSS Level 1 for cards.

Last updated August 30, 2026. Report issues to [email protected].

What we actually operate

Accounts
Dashboard sessions use HTTP-only cookies. Email/password and OAuth providers are supported where configured. You can delete an account from Settings.
API keys
Bearer tokens required on API requests. Secrets are hashed at rest and shown in full only at creation. Rotate by creating a new key before revoking the old one.
Data
API request and response content is logged to operate billing, debugging, and the service. We do not train foundation models on your prompts or completions by default. See the data policy.
Billing
Card numbers are processed by Stripe. Caedral does not store complete PAN data. Usage is ledgered per request against subscription pools.
Network
API and dashboard traffic uses TLS 1.2 or higher. Production access is least-privilege and logged.
Platform safeguards
Rate limits, HTTP 402 when spend is unavailable, and key scoping to your account. Team members consume the team pool while that team is their billing target.

Full practices

Last updated August 30, 2026. Responsible disclosure: [email protected].

Security is foundational to Caedral's infrastructure. This page describes how we protect the Service, your data, and API access. It provides a high-level overview of our practices and is not a contractual commitment unless expressly incorporated into a signed agreement with Caedral.

Security inquiries: [email protected].

Infrastructure

  • Production systems run on hardened cloud infrastructure with network segmentation between environments
  • Production access is restricted to authorized personnel, granted on a least-privilege basis, and logged
  • Infrastructure changes follow peer review and controlled deployment procedures
  • Development, staging, and production environments are logically separated

Encryption

  • All API and dashboard traffic is encrypted in transit using TLS 1.2 or higher
  • Data at rest is encrypted using industry-standard algorithms on cloud provider infrastructure
  • API keys are stored using one-way hashing; full secret keys are displayed only once at creation
  • Secrets and credentials are managed through dedicated secrets management tooling, not source code

Authentication and access control

  • All API requests require a valid bearer token tied to your account
  • Dashboard sessions use secure, HTTP-only cookies with appropriate expiration
  • Team and role-based access controls are available on eligible plans
  • API keys can be rotated without service interruption by creating a new key before revoking the old one
  • We monitor for anomalous authentication patterns and may suspend keys that appear compromised

Application security

  • Code changes undergo review before deployment to production
  • Dependencies are monitored for known vulnerabilities
  • Input validation and rate limiting are enforced at the API layer
  • We conduct periodic security assessments of critical systems

Monitoring and incident response

We monitor the Service continuously for anomalies, abuse, and security events. Our incident response process includes detection, containment, investigation, remediation, and post-incident review.

SeverityDescriptionCustomer notification
CriticalConfirmed breach of customer data or API keysWithin 72 hours of confirmation, where required by law
HighService compromise affecting availability or integrityStatus update within 24 hours via email or dashboard
MediumSecurity event contained without customer data impactNotification if customer action is required
LowMinor issue with no customer impactNo notification unless relevant to your account

If you believe your account or API keys have been compromised, rotate your keys immediately and contact [email protected].

Payment security

Payment processing is handled entirely by Stripe, Inc., a PCI DSS Level 1 certified payment processor. Caedral does not store, process, or transmit complete payment card numbers on our systems. Billing data received from Stripe is handled according to our Privacy Policy.

Vulnerability disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in the Service, report it to [email protected]. Include a description, steps to reproduce, and potential impact. You may also report through our Discord community for initial triage, but email is preferred for sensitive reports.

Safe harbor

If you make a good-faith effort to comply with this policy — including allowing reasonable time for us to investigate and remediate before public disclosure — Caedral will not initiate legal action against you for security research conducted in accordance with these guidelines. Do not access data belonging to other users, disrupt the Service, or engage in social engineering against Caedral personnel or users.

Out of scope

  • Denial-of-service attacks against production infrastructure
  • Physical security testing of Caedral facilities or personnel
  • Social engineering or phishing against employees or users
  • Issues in third-party services not operated by Caedral
  • Findings from automated scanners without demonstrated impact

Data processing and enterprise

Enterprise customers may request a Data Processing Agreement (DPA), security questionnaire completion, or subprocessor list by contacting [email protected]. We respond to reasonable security assessments within 15 business days.

Compliance posture

Caedral designs security practices with common industry frameworks in mind, including SOC 2 trust principles and NIST guidance. We have not yet completed a formal SOC 2 audit. As the platform matures, we intend to pursue independent security certifications and will update this page when achieved.

We do not currently hold formal HIPAA, PCI DSS (direct), FedRAMP, or ISO 27001 certifications. Customers with specific compliance requirements should contact [email protected] before deploying regulated workloads.