Last Updated: June 2026

Security

How Candor protects customer information through industry-standard practices, operational safeguards, and continuous monitoring.

At Candor, security is built into every aspect of the platform, from design and development to deployment and operations.

Our goal is to provide customers with a secure and reliable platform while maintaining transparency regarding our security and privacy practices.

Metadata-Only Architecture

Candor operates on a Metadata-Only Architecture. Candor reads database system catalogs and schema metadata to generate data mart designs. Candor does not copy, store, or cache raw transactional rows, enterprise PII, or operational business records on its remote cloud servers. All actual data transformation payloads run localized or tunnelled within isolated execution contexts.

This architecture helps reduce data movement, minimize compliance exposure, and provide customers with greater control over sensitive enterprise information.

Privacy and Compliance

Candor is committed to supporting customer privacy and data protection requirements. Our practices are designed with widely recognized privacy principles in mind, including requirements commonly associated with regulations such as GDPR and CCPA.

Our privacy practices are designed to support compliance efforts relating to GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and related frameworks. Additional information regarding our data handling practices can be found in our Privacy Policy.

Payment Security

Payments for Candor services are securely processed by Paddle, our Merchant of Record.

Candor does not collect, process, store, or have access to customers' full payment card information. Payment information is handled directly by Paddle in accordance with applicable payment security standards.

This approach helps reduce security risks and supports PCI DSS compliance requirements.

Data Protection

We implement technical and organizational measures designed to help protect customer data against unauthorized access, disclosure, alteration, loss, or destruction.

Our security approach includes:

  • Secure system architecture and infrastructure design
  • Access controls and authentication mechanisms
  • Continuous monitoring and logging
  • Backup and recovery procedures
  • Security-focused software development practices
  • Regular maintenance and software updates

Encryption

Data in Transit

Data transmitted between users, applications, and platform services is protected using industry-standard encryption protocols such as TLS (Transport Layer Security).

Data at Rest

Where applicable, stored customer data is protected using encryption mechanisms designed to safeguard information from unauthorized access.

Access Controls

Access to systems and customer data is restricted to authorized personnel who require access for operational, support, security, or maintenance purposes.

Security controls may include:

  • Role-based access controls (RBAC)
  • Strong authentication requirements
  • Principle of least privilege
  • Access review procedures
  • Account monitoring and access management

Audit Logging and Monitoring

Candor maintains operational and security logs to support security monitoring, incident investigation, operational troubleshooting, platform reliability, and compliance and audit requirements.

Logging activities may include authentication events, access attempts, platform activity, and system events.

Infrastructure Security

Candor utilizes modern cloud infrastructure and security best practices designed to help ensure platform reliability, availability, and protection of customer information.

Infrastructure security measures may include:

  • Network segmentation and isolation
  • Firewall and access control configurations
  • Infrastructure monitoring and alerting
  • Secure deployment and configuration management
  • Environment separation between development, testing, and production systems

Application Security

Security considerations are incorporated throughout the software development lifecycle.

Our development and release processes may include:

  • Secure coding practices
  • Code review procedures
  • Dependency and vulnerability monitoring
  • Security testing before deployment
  • Ongoing maintenance and updates

Backup and Recovery

We maintain backup and recovery procedures designed to support business continuity and data availability.

Backup processes may include:

  • Scheduled backups
  • Recovery testing
  • Disaster recovery planning
  • Infrastructure redundancy where appropriate

Vulnerability Management

Candor works to identify, assess, and remediate security vulnerabilities through ongoing monitoring and security reviews.

Security activities may include:

  • Software updates and patch management
  • Vulnerability assessments
  • Security testing
  • Infrastructure monitoring
  • Risk evaluation and remediation

Security Incident Response

Candor maintains procedures for investigating, managing, and responding to security incidents.

When appropriate and required by applicable law, affected customers will be notified of confirmed incidents involving their personal information or customer data.

Service Availability

Candor is committed to maintaining a reliable and available platform.

Our operational practices may include:

  • Platform monitoring
  • Incident management procedures
  • Backup and recovery processes
  • Planned maintenance management
  • Availability and performance monitoring

Responsible Disclosure

If you believe you have identified a security vulnerability affecting the Candor, please report it responsibly.

Please include:

  • Description of the issue
  • Steps to reproduce the issue
  • Potential impact
  • Supporting screenshots or logs, if available

Candor will review legitimate reports and take appropriate action to investigate and address verified security concerns.

Customer Responsibilities

Customers are responsible for:

  • Protecting account credentials
  • Managing user access permissions
  • Maintaining endpoint and device security
  • Reviewing platform-generated outputs before production use
  • Maintaining appropriate security practices within their own environments

Security Certifications

Candor continuously evaluates its security controls and operational practices.

While Candor may align its security practices with industry standards and best practices, any certifications, audits, or compliance attestations will be disclosed separately when applicable.

Contact

For security-related questions or to report a potential security concern, please contact:

Email: support@candorsys.com

For general support inquiries, please use our Contact Us page or email the support team.