Skip to content
Security & data handling

Protect valuable product data with clear boundaries.

Cailar treats commercial and technical catalog files as sensitive business information. Controls, responsibilities, and implementation status are reviewed before data transfer.

No certification logo or assurance is displayed before it is actually obtained.
No public catalog upload

The website collects business qualification details only.

Qualified secure process

NDA, controls, retention, and transfer are agreed first.

Published control status

Implemented, available, planned—or not offered.

This page distinguishes website protections from contracted product controls. Customer-specific requirements are documented before a secure workspace is enabled.

ControlStatusWhat it means
TLS for marketing-site trafficImplemented

The published website is served over HTTPS by the deployment platform.

Public confidential-data uploadNot offered

Catalog files are not accepted through public website forms.

Qualified secure transferContracted scope

A private transfer path is agreed after qualification, NDA, and security review.

Customer data for model trainingPermission required

Cailar’s operating policy prohibits training on customer catalogs without contractual permission.

Access and approval loggingAvailable

Product-workspace controls and responsibilities are documented in the customer’s agreed deployment scope.

Independent security assessmentPlanned

No independent assessment is claimed before it is completed and documented.

SOC 2 Type IIPlanned

No certification is claimed before it is obtained.

Before catalog intake

Questions resolved in the customer security review.

Exact answers depend on the contracted architecture and approved processing workflow—not a generic marketing promise.

Hosting and encryption

Hosting region, encryption in transit and at rest, key responsibilities, and environment boundaries.

Access and isolation

Authorized roles, employee access, customer isolation, review permissions, and audit logging.

Retention and deletion

Retention period, backups, deletion procedure, secure disposal, and contract-end responsibilities.

Models and subprocessors

Approved AI providers, data flows, model training terms, subprocessors, and change notification.

Incidents and assurance

Incident notification, assessment status, available evidence, and contractual security documents.

Transfer and onboarding

NDA, data minimization, secure intake, permitted file types, and named customer contacts.

A practical first step

Review security before sharing product data.

Tell us the business workflow first. Detailed security requirements, contractual documents, and secure transfer are handled during qualification.

Speak with security