Calispec

Calispec Trust Center

At Calispec, maintaining the highest standards of security and privacy comes first. We are committed to delivering enterprise-grade gauge management and calibration software by protecting your data and ensuring a safe, audit-ready experience for manufacturers worldwide.

Security Practices

How Calispec designs, builds, and operates Calispec GMS securely across every layer of the stack

Access Control

  • MFA enforced for all user accounts and admin interfaces
  • Least-privilege RBAC across all GMS modules, reviewed quarterly
  • Privileged access separated from standard accounts

Encryption

  • AES-256 encryption for all data at rest
  • TLS 1.2+ enforced for all data in transit; TLS 1.0/1.1 disabled
  • Encryption keys managed in dedicated KMS, rotated annually

Vulnerability Management

  • Annual VAPT by accredited third-party firm
  • Critical CVEs patched within 72 hours; high severity within 14 days
  • SAST and DAST integrated into CI/CD pipeline

Secure SDLC

  • Code review required for all changes before merge
  • Static analysis on every pull request
  • Dependency vulnerability scanning on every build

Incident Response

  • Documented IR plan with defined roles and escalation paths
  • Customer breach notification within 72 hours of confirmed incident
  • Post-incident root-cause analysis for all P1/P2 events

Cloud & Infrastructure

  • Hosted on AWS ap-south-1 (Mumbai); ISO 27001 and SOC 2 certified provider
  • Production environment isolated via separate VPCs from staging and dev
  • IDS/IPS monitoring active on all production network interfaces

Logging & Monitoring

  • Centralised logging for all production systems
  • Real-time alerting on anomalous access patterns
  • Log retention: minimum 1 year for all security events

Third-Party Risk

  • All subprocessors assessed against ISO 27001 or SOC 2 before onboarding
  • Annual subprocessor review
  • Full subprocessor list published on the Subprocessors tab