Security & Privacy

Your data is secure

Calendar sync requires trust. Here's how we protect your sensitive information.

End-to-End Encryption
All data is encrypted in transit and at rest using industry-standard AES-256 encryption.
Zero Trust Architecture
We never store your calendar events. Only minimal metadata needed for sync operations is retained.
Privacy Controls
You control exactly what information gets shared with granular privacy settings.
SOC 2 Compliant Infrastructure
Our infrastructure meets SOC 2 Type II standards for security and availability.
GDPR Compliant
Full compliance with GDPR. Request data export or deletion at any time.
Audit Logs
Complete audit trail of all sync operations and data access for transparency.
Data Protection

What we store:

  • • Sync rule configurations
  • • Event metadata for duplicate detection
  • • Calendar connection tokens (encrypted)
  • • Activity logs for troubleshooting

What we never store:

  • • Full calendar event contents
  • • Meeting descriptions or notes
  • • Attendee email addresses
  • • Personal information from events
Infrastructure

Hosting & Security:

  • • Hosted on enterprise-grade cloud infrastructure
  • • 99.9% uptime SLA with automated failover
  • • Regular security audits and penetration testing
  • • 24/7 monitoring and threat detection

Access Controls:

  • • Multi-factor authentication required
  • • Role-based access with principle of least privilege
  • • All access logged and audited
  • • Regular access reviews and deprovisioning

Our Privacy Commitment

We built Caltsu with privacy by design. Your calendar data belongs to you, and we're simply the secure bridge between your calendars. We will never sell your data, share it with third parties, or use it for advertising.

Have security questions or want to report a vulnerability?

security@caltsu.com