Security | Custral
Trust & Security

Security at Custral

Custral runs your email, messaging, calls, and customer records, so protecting that data is foundational. Here’s how we keep it safe — and where to find the details.

SOC 2 Type II — in progressEncrypted in transit & at restGDPR & CCPA ready
How we protect your data

Encryption everywhere

Your data is encrypted in transit with TLS and at rest.

Role-based access

Granular, role-based permissions on every object, with least-privilege access and multi-factor authentication for our team.

Activity logging

Every change is recorded and attributable, so you always know who did what.

Compliance

A SOC 2 Type II examination is in progress with an independent auditor, and the platform is built to support GDPR and CCPA.

Infrastructure

Hosted on Amazon Web Services in the United States, with continuous monitoring and regular backups.

Guest access

External guests and shared links see only the records you choose to share — nothing more.

Data privacy

We handle the data you run through Custral as a processor, under a Data Processing Addendum, and we never sell it.

Incident response

We monitor for security issues and will notify affected customers of a data breach as the law requires.

Report a vulnerability

Found a security issue? We appreciate responsible disclosure. Email security@custral.com with the details and steps to reproduce, and we’ll respond promptly. Please give us a reasonable chance to address the issue before disclosing it publicly.