Security your reviewers can sign off

Celentra runs outbound at scale on infrastructure built for teams under real controls: encryption everywhere, least-privilege access, independent audits, and the documentation your reviewers ask for on day one.

Continuous control monitoring, not an annual snapshot

Every workspace runs against the same hardened baseline. Controls are monitored continuously and evidence is collected automatically, so audits reflect how the platform actually runs.

142 of 145 monitored controls are passing. The remaining three are scheduled access reviews, not open findings.

Control monitorsLive
  • Encryption at rest and in transitEnforced
  • MFA on all internal accountsEnforced
  • Dependency and image scanningClean
  • Access reviewsDue in 9 days
Automated scansLast 7 days

Encrypted by default

AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.

Least privilege

Internal access is role-scoped, time-bound, approved in advance, and logged for review.

Tenant isolation

Every workspace is logically isolated, with authorisation checks enforced at the data layer.

Always watching

Centralised logging, anomaly detection, and paged on-call coverage around the clock.

SOC 2 Type IIIndependently audited annually
GDPR and CCPADPA and SCCs available
Penetration testedThird-party tests twice a year
Vetted teamBackground checks and annual training

What reviewers
ask us most

Yes. We share the full SOC 2 Type II report, along with our latest penetration test summary, under a mutual NDA. Ask your account team or use the contact form and we will send it over the same day.

Data is hosted with major cloud providers in the region assigned to your workspace, replicated across availability zones for resilience. Enterprise plans can pin campaign data to a specific region for residency requirements.

Support engineers cannot read workspace data by default. Access requires a ticket, an approval, and a time-boxed elevation that expires automatically, and every session is logged and reviewable in your audit log.

No. Content in a customer workspace is never used to train models that serve other customers. Model features run on your data only to produce output for your workspace.

We run a documented incident response process with defined severity levels and on-call ownership. For confirmed incidents affecting your data we notify named contacts within 24 hours and follow up with a written post-incident report.

Send findings to security@celentra.io. We acknowledge reports within one business day, trade updates while we investigate, and credit researchers who report responsibly.

Send us your security questionnaire