Third Party Index

Snapshot 23050

Document
Security page
URL
https://cal.com/security
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
871831 bytes
SHA-256 (raw)
bf5705217f0e8e1585421f71fa4d7bc1ce19a31c7246542512b997d97b9342a5
SHA-256 (normalized text)
dbfdebb44f67c12c83eb795b1758858ae73d717baff9110c74e6574ff5d95b15

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Solutions
Enterprise
Cal.ai
Developer
Resources
Pricing
Sign in
Get started
Sign in
Get started
Solutions
Solutions
By team size
For Individuals
Personal scheduling made simple
For Teams
Collaborative scheduling for groups
For Organizations
Larger teams scheduling for more control & security
For Enterprises
Enterprise-level scheduling solutions
By use case
Recruiting
Sales
HR
Education
Support
Healthcare
Telehealth
Marketing
Try Cal.ai now!
Supercharged scheduling with AI-powered calls
Enterprise
Developer
Developer Documentation
Documentation for the Cal.com platform
API
Build your own integrations with our public API
Scheduling Components
Use our react atoms to add scheduling to your app
Create OAuth Client
Integrate Cal.com using OAuth
Resources
Font: Cal Sans UI & Text
Our own variable typeface for user interface design
App Store
Integrate with your favorite apps
Collective Events
Schedule events with multiple participants
Help Docs
Need to learn more about our system? Check the help docs
Embed
Embed Cal.com into your website
Out Of Office
Schedule time off with ease
Payments
Accept payments for bookings
Workflows
Automate scheduling and reminders
Blog
Stay up to date with the latest news and updates
Instant Meetings
Meet with clients in minutes
Dynamic Group Links
Seamlessly book meetings with multiple people
Webhooks
Get notified when something happens
Cal.ai
Pricing
Security
Compliance
Access compliance documents, certifications, and data protection agreements
Data Protection Agreement
Download
SOC 2 Type II report
Download
ISO 27001 Certification
Download
Penetration test report
Download
Security
As a company that has achieved ISO 27001, SOC 2 Type II, CCPA, GDPR, and HIPAA certifications, we understand the critical importance of information security in today's digital landscape. The increasing frequency and sophistication of cyber attacks highlight the necessity for businesses to prioritize security to safeguard their data and ensure the trust and confidence of their clients. By implementing industry-standard security measures and best practices, we demonstrate our unwavering commitment to the protection of sensitive information and the preservation of the integrity of our operations. We take pride in the rigorous security protocols we have in place and are dedicated to maintaining the highest standards of security excellence.
How has this been accomplished?
As an organization, we understand the importance of maintaining compliance with security practices and standards. That's why we utilize security and compliance automation platforms to ensure that we remain continuously compliant and adhere to the relevant security protocols.
We have a centralized platform that automates the assessment and monitoring of various security controls and procedures. By integrating with our existing systems and tools, our platforms provide us with a comprehensive view of our security posture, identifying any potential issues and ensuring that we are always up to date with the latest security protocols and industry standards. This gives us the confidence that we are following industry best practices and that we are providing a secure environment for our customers and stakeholders.
What happens if something becomes out of compliance?
If something were to fall out of compliance, our compliance automation platform would detect the issue and alert us immediately. This would allow us to take prompt action to address the problem and get back into compliance quickly. By using a compliance automation platform like this, we can stay on top of our compliance obligations and take proactive steps to ensure that we remain compliant with the relevant security practices and standards. This gives us the confidence that we are providing a secure environment for our clients and stakeholders and helps us to maintain our reputation as a reliable and trustworthy organization.
Procedures & controls
Secure policies & procedures
Written information security policies and procedures ensure that the company has documented and tested controls in place to protect customer data and respond to security incidents effectively.
Vulnerability & penetration testing
Regular vulnerability and penetration testing help to identify and address potential security weaknesses before they can be exploited by attackers. Cal.com undergoes an external penetration test of our web application annually by a third party to identify any security vulnerabilities we may have, this will then allow us to raise these issues internally and remediate them immediately. An official report is created to Cal.com stating that the issues found are now fixed. We also conduct regular internal penetration tests. We also employ automated vulnerability scanning within our code and it’s dependencies.
Data encryption
Encryption of sensitive data helps to ensure that the data cannot be accessed or read by unauthorized parties. Having our database encrypted allows customers to feel safe when using our product as it safeguards data when in transit or at rest.
Multi-factor authentication
Multi-factor authentication helps to prevent unauthorized access to the company's systems, which can help to protect customer data from theft or tampering.
Secure development lifecycle
Multi-factor authentication helps to prevent unauthorized access to the company's systems, which can help to protect customer data from theft or tampering. All changes to our codebase are protected with branch protection, meaning that to be able to push a new code change to production, the code change must have been approved by another engineer, as well as the code change has to pass a number of automated tests that check for security issues introduced by the code or it’s dependencies, as well as end-to-end testing and more. This way, no bad actors internal or external to Cal.com are able to push malicious code due to our secure reviews process.
Monitoring
Ongoing monitoring of system access logs and network traffic helps to detect and respond to potential security incidents, reducing the likelihood of customer data being compromised.
Employee training & awareness
Regular training and awareness programs for employees help to ensure that they are equipped to handle customer data securely, reducing the likelihood of human error or intentional data breaches. We make it a priority that these are completed straight away for all new employees and completed annually for all existing employees.
Access controls & background checks
Access controls and background checks for employees, third-party vendors and service providers help to ensure that they are trustworthy and can be relied upon to handle customer data securely. Background checks are performed on all new hires the company may conduct as a way for Cal.com to establish confidence in the employee we are choosing to hire. Additionally, only giving access to applications for particular applications is important in staying compliant. Every quarter we review application access and access levels for all employees to make sure they only have access to applications which are required to perform their job role.
Third-party audits and assessments
Regular third-party audits and assessments provide an independent validation of the effectiveness of the company's information security controls and procedures, providing customers with confidence that their data is being handled securely.
Intrusion detection
Cal.com utilizes intrusion detection systems to continuously monitor our systems for potential threats that may occur at any time. Knowing at the early stages that a threat could be critical allows us to act quickly and efficiently to prevent any threats from causing short or long term issues.
Vulnerability disclosure
At Cal.com, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.
If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.
Out of scope vulnerabilities:
Clickjacking.
Cross-Site Request Forgery (CSRF)
Attacks requiring MITM or physical access to a user's device.
Any activity that could lead to the disruption of our service (DoS).
Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
SPF Email spoofing
Missing DNSSEC, CAA, CSP headers
Lack of Secure or HTTP only flag on non-sensitive cookies
Deadlinks
Anything related to DNS or email security
Rate Limiting
XSS (Cross-Site Scripting)
Note: Cal.com reserves the right to designate any reported vulnerability as out of scope.
What to do and what not to do
Do not run automated scanners on our infrastructure or dashboard. If you wish to do this, contact us and we will set up a sandbox for you.
Do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability or deleting or modifying other people's data,
Do not reveal the problem to others until it has been resolved,
Do not use attacks on physical security, social engineering, distributed denial of service, spam or applications of third parties, and
How to report a vulnerability
You can report vulnerabilities here: https://bugcrowd.com/4f0b96d4-2749-415e-b2d8-6aebde98f211/external/report
In scope: Cal.com QA Environment
Only the targets listed below are authorized for security testing: (edited)
Target
URL
Type
Cal.com QA
https://app.cal.qa/
Website testing
Cal.com QA API
https://api.cal.qa/
API testing
You may create and use multiple test accounts within the QA environment when necessary, as long as you use only accounts and test data you control.
Once we have received your submission, there may be a delay in getting back to you whilst our team triages the issue.
Please provide sufficient information to reproduce the problem, so we will be able to resolve it as quickly as possible. Usually, the IP address or the URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.
If you have followed the instructions above, we will not take any legal action against you in regard to the report
We will handle your report with strict confidentiality, and not pass on your personal details to third parties without your permission
We will keep you informed of the progress towards resolving the problem
In the public information concerning the problem reported, we will give your name as the discoverer of the problem (unless you desire otherwise)
We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.
Cal.com® and Cal® are registered trademarks
of Cal.com, Inc. All rights reserved.
Our mission is to connect a billion people by 2031
through calendar scheduling.
Select Language
English
Downloads
Android
Chrome
Safari
Edge
Firefox
macOS
Windows
Linux
Need Help? [email protected] or visit cal.com/help.
Solutions
iOS/Android App
Self-hosted
Pricing
Docs
Cal.ai - AI Phone Agent
Enterprise
Integrate Cal.com
Routing
Cal.com Atoms
Desktop App
FAQ
Enterprise API
GitHub
Docker
Use Cases
Sales
Marketing
Talent Acquisition
Customer Support
Higher Education
Telehealth
Professional Services
Hiring Marketplace
Human Resources
Tutoring
C-suite
Law
Resources
Affiliate Program
Help Docs
Blog
Cal Fonts
Teams
Embed
Recurring events
Developers
OOO
Workflows
Instant Meetings
App Store
Requires confirmation
Payments
Video Conferencing
Cal.com vs Calendly
Company
Jobs
About
Open Startup
Support
Privacy
Terms
License
Security
Changelog
Get a demo
Talk to sales
Cal.com® and Cal® are registered trademarks
of Cal.com, Inc. All rights reserved.
Our mission is to connect a billion people by 2031
through calendar scheduling.
Select Language
English
Downloads
Android
Chrome
Safari
Edge
Firefox
macOS
Windows
Linux
Need Help? [email protected] or visit cal.com/help.
Solutions
iOS/Android App
Self-hosted
Pricing
Docs
Cal.ai - AI Phone Agent
Enterprise
Integrate Cal.com
Routing
Cal.com Atoms
Desktop App
FAQ
Enterprise API
GitHub
Docker
Use Cases
Sales
Marketing
Talent Acquisition
Customer Support
Higher Education
Telehealth
Professional Services
Hiring Marketplace
Human Resources
Tutoring
C-suite
Law
Resources
Affiliate Program
Help Docs
Blog
Cal Fonts
Teams
Embed
Recurring events
Developers
OOO
Workflows
Instant Meetings
App Store
Requires confirmation
Payments
Video Conferencing
Cal.com vs Calendly
Company
Jobs
About
Open Startup
Support
Privacy
Terms
License
Security
Changelog
Get a demo
Talk to sales
Cal.com® and Cal® are registered trademarks
of Cal.com, Inc. All rights reserved.
Our mission is to connect a billion people by 2031
through calendar scheduling.
Select Language
English
Downloads
Android
Chrome
Safari
Edge
Firefox
macOS
Windows
Linux
Need Help? [email protected] or visit cal.com/help.
Solutions
iOS/Android App
Self-hosted
Pricing
Docs
Cal.ai - AI Phone Agent
Enterprise
Integrate Cal.com
Routing
Cal.com Atoms
Desktop App
FAQ
Enterprise API
GitHub
Docker
Use Cases
Sales
Marketing
Talent Acquisition
Customer Support
Higher Education
Telehealth
Professional Services
Hiring Marketplace
Human Resources
Tutoring
C-suite
Law
Resources
Affiliate Program
Help Docs
Blog
Cal Fonts
Teams
Embed
Recurring events
Developers
OOO
Workflows
Instant Meetings
App Store
Requires confirmation
Payments
Video Conferencing
Cal.com vs Calendly
Company
Jobs
About
Open Startup
Support
Privacy
Terms
License
Security
Changelog
Get a demo
Talk to sales