Skip to content
Security & Compliance

Your data. Your control. Our commitment.

Military-grade encryption, zero-knowledge AI training, and transparent data practices. Building trust through security, not promises.

Compliance & Certifications

SOC 2 Type II
In Progress

Audited security controls and processes

ETA: Q2 2025

GDPR Compliant
Active

Full EU data protection compliance

CCPA Compliant
Active

California privacy rights protected

ISO 27001
Roadmap

Information security management

ETA: 2025

HIPAA
Available

Healthcare compliance (BAA available)

Privacy Shield
Active

US-EU data transfer framework

Security Infrastructure

AES-256 Encryption

All data encrypted at rest and in transit using military-grade encryption

Infrastructure Security

Hosted on AWS with multi-region redundancy and automatic failover

Zero-Knowledge Architecture

Your calendar data never trains models for other users

Audit Logging

Complete audit trail of all data access and modifications

Access Controls

Role-based access control with principle of least privilege

Incident Response

24-hour breach notification with dedicated security team

Data Protection & Privacy

Sub-Processors & Vendors

All vendors sign Data Processing Agreements and undergo security review
VendorPurposeLocationCompliance
Amazon Web ServicesInfrastructure hostingUS/EUSOC 2, ISO 27001, HIPAA
StripePayment processingUSPCI DSS Level 1, SOC 2
SendGridTransactional emailUSSOC 2, GDPR
CloudflareCDN and DDoS protectionGlobalSOC 2, GDPR
DatadogMonitoring (no PII)USSOC 2, GDPR

Security Best Practices

How we protect your data every day

Development Security

  • • Code review on every change
  • • Automated security scanning
  • • Dependency vulnerability monitoring
  • • Secure development lifecycle (SDLC)

Operational Security

  • • 24/7 monitoring and alerting
  • • Automated threat detection
  • • Regular penetration testing
  • • Disaster recovery drills

Employee Security

  • • Background checks
  • • Security training
  • • Limited access principles
  • • Hardware encryption required
Security Questions?
Our security team is here to help with compliance reviews and security assessments

Bug Bounty

security@vardacal.com

DPA Requests

legal@vardacal.com

Compliance Docs

compliance@vardacal.com