SECURITY

Your plant data is protected.

We do not sell, share, or monetize your data. Every layer of CastOS is built with security as a requirement.

Encryption everywhere

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Database connections use SSL. No exceptions.

Organization-scoped isolation

Every database query is scoped to your organization. There is no cross-tenant access. Your data is invisible to other customers.

Role-based access control

Granular permissions by role. Admins control who sees what. Multi-factor authentication support and SSO readiness.

Full audit trail

Every action is logged - who did what, when, and why. Create, update, delete, and AI-assisted changes are all recorded with timestamps and user attribution.

Responsible AI data handling

AI features process your data to deliver results within CastOS. Your data is never used to train AI models. Our AI providers are contractually prohibited from using customer data for training purposes.

Infrastructure you can trust

Deployed with automatic failover and high availability. Database with point-in-time recovery. Encrypted file storage. Every layer protected in transit and at rest.

OUR COMMITMENT

Your data belongs to you. You can export or delete it at any time.

We do not sell your data to third parties. Ever.

AI providers process data only to deliver results. They do not retain or train on it.

Every query is scoped to your organization. No cross-tenant access is possible.

All actions are logged with full attribution for audit and compliance purposes.

Responsible Disclosure

If you discover a security vulnerability, please report it to security@castlabs.ai.