Trust

Security at Cairn

Your plan is your company's most sensitive document after payroll. Here is how we look after it.

Infrastructure

  • Hosted on AWS in eu-west-1 and us-east-1; you choose the region on the Business plan
  • Encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Daily backups retained for 30 days, tested restores every month

Access

  • SAML SSO and SCIM provisioning on Business
  • Role-based permissions and per-project guests on every plan
  • Audit log of every sign-in, permission change and export

Practice

  • SOC 2 Type II report available under NDA
  • Annual third-party penetration test
  • A responsible disclosure programme with a public security.txt

SOC 2

Type II report available under NDA.

GDPR

Data processing agreement on request; EU residency on Business.

99.9%

Uptime SLA on Business, with public status history.

Need the questionnaire filled in?

Send us yours, or use our completed CAIQ. Either way, a person answers.

Contact security