SECURITY
Your plant data is protected.
We do not sell, share, or monetize your data. Every layer of CastOS is built with security as a requirement.
Encryption everywhere
All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Database connections use SSL. No exceptions.
Organization-scoped isolation
Every database query is scoped to your organization. There is no cross-tenant access. Your data is invisible to other customers.
Role-based access control
Granular permissions by role. Admins control who sees what. Multi-factor authentication support and SSO readiness.
Full audit trail
Every action is logged - who did what, when, and why. Create, update, delete, and AI-assisted changes are all recorded with timestamps and user attribution.
Responsible AI data handling
AI features process your data to deliver results within CastOS. Your data is never used to train AI models. Our AI providers are contractually prohibited from using customer data for training purposes.
Infrastructure you can trust
Deployed with automatic failover and high availability. Database with point-in-time recovery. Encrypted file storage. Every layer protected in transit and at rest.
OUR COMMITMENT
Your data belongs to you. You can export or delete it at any time.
We do not sell your data to third parties. Ever.
AI providers process data only to deliver results. They do not retain or train on it.
Every query is scoped to your organization. No cross-tenant access is possible.
All actions are logged with full attribution for audit and compliance purposes.
Responsible Disclosure
If you discover a security vulnerability, please report it to security@castlabs.ai.