Encrypted by default
AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.
Celentra runs outbound at scale on infrastructure built for teams under real controls: encryption everywhere, least-privilege access, independent audits, and the documentation your reviewers ask for on day one.
Every workspace runs against the same hardened baseline. Controls are monitored continuously and evidence is collected automatically, so audits reflect how the platform actually runs.
142 of 145 monitored controls are passing. The remaining three are scheduled access reviews, not open findings.
AES-256 at rest and TLS 1.3 in transit, with keys managed and rotated in a dedicated KMS.
Internal access is role-scoped, time-bound, approved in advance, and logged for review.
Every workspace is logically isolated, with authorisation checks enforced at the data layer.
Centralised logging, anomaly detection, and paged on-call coverage around the clock.
Yes. We share the full SOC 2 Type II report, along with our latest penetration test summary, under a mutual NDA. Ask your account team or use the contact form and we will send it over the same day.
Data is hosted with major cloud providers in the region assigned to your workspace, replicated across availability zones for resilience. Enterprise plans can pin campaign data to a specific region for residency requirements.
Support engineers cannot read workspace data by default. Access requires a ticket, an approval, and a time-boxed elevation that expires automatically, and every session is logged and reviewable in your audit log.
No. Content in a customer workspace is never used to train models that serve other customers. Model features run on your data only to produce output for your workspace.
We run a documented incident response process with defined severity levels and on-call ownership. For confirmed incidents affecting your data we notify named contacts within 24 hours and follow up with a written post-incident report.
Send findings to security@celentra.io. We acknowledge reports within one business day, trade updates while we investigate, and credit researchers who report responsibly.