Security at Custral
Custral runs your email, messaging, calls, and customer records, so protecting that data is foundational. Here’s how we keep it safe — and where to find the details.
Encryption everywhere
Your data is encrypted in transit with TLS and at rest.
Role-based access
Granular, role-based permissions on every object, with least-privilege access and multi-factor authentication for our team.
Activity logging
Every change is recorded and attributable, so you always know who did what.
Compliance
A SOC 2 Type II examination is in progress with an independent auditor, and the platform is built to support GDPR and CCPA.
Infrastructure
Hosted on Amazon Web Services in the United States, with continuous monitoring and regular backups.
Guest access
External guests and shared links see only the records you choose to share — nothing more.
Data privacy
We handle the data you run through Custral as a processor, under a Data Processing Addendum, and we never sell it.
Incident response
We monitor for security issues and will notify affected customers of a data breach as the law requires.
Read the details
A Data Processing Addendum (DPA) is available to customers on request — email privacy@custral.com.
Report a vulnerability
Found a security issue? We appreciate responsible disclosure. Email security@custral.com with the details and steps to reproduce, and we’ll respond promptly. Please give us a reasonable chance to address the issue before disclosing it publicly.