Last Updated: June 2026
Security
How Candor protects customer information through industry-standard practices, operational safeguards, and continuous monitoring.
At Candor, security is built into every aspect of the platform, from design and development to deployment and operations.
Our goal is to provide customers with a secure and reliable platform while maintaining transparency regarding our security and privacy practices.
Candor operates on a Metadata-Only Architecture. Candor reads database system catalogs and schema metadata to generate data mart designs. Candor does not copy, store, or cache raw transactional rows, enterprise PII, or operational business records on its remote cloud servers. All actual data transformation payloads run localized or tunnelled within isolated execution contexts.
This architecture helps reduce data movement, minimize compliance exposure, and provide customers with greater control over sensitive enterprise information.
Privacy and Compliance
Candor is committed to supporting customer privacy and data protection requirements. Our practices are designed with widely recognized privacy principles in mind, including requirements commonly associated with regulations such as GDPR and CCPA.
Our privacy practices are designed to support compliance efforts relating to GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and related frameworks. Additional information regarding our data handling practices can be found in our Privacy Policy.
Payment Security
Payments for Candor services are securely processed by Paddle, our Merchant of Record.
Candor does not collect, process, store, or have access to customers' full payment card information. Payment information is handled directly by Paddle in accordance with applicable payment security standards.
This approach helps reduce security risks and supports PCI DSS compliance requirements.
Data Protection
We implement technical and organizational measures designed to help protect customer data against unauthorized access, disclosure, alteration, loss, or destruction.
Our security approach includes:
- Secure system architecture and infrastructure design
- Access controls and authentication mechanisms
- Continuous monitoring and logging
- Backup and recovery procedures
- Security-focused software development practices
- Regular maintenance and software updates
Encryption
Data in Transit
Data transmitted between users, applications, and platform services is protected using industry-standard encryption protocols such as TLS (Transport Layer Security).
Data at Rest
Where applicable, stored customer data is protected using encryption mechanisms designed to safeguard information from unauthorized access.
Access Controls
Access to systems and customer data is restricted to authorized personnel who require access for operational, support, security, or maintenance purposes.
Security controls may include:
- Role-based access controls (RBAC)
- Strong authentication requirements
- Principle of least privilege
- Access review procedures
- Account monitoring and access management
Audit Logging and Monitoring
Candor maintains operational and security logs to support security monitoring, incident investigation, operational troubleshooting, platform reliability, and compliance and audit requirements.
Logging activities may include authentication events, access attempts, platform activity, and system events.
Infrastructure Security
Candor utilizes modern cloud infrastructure and security best practices designed to help ensure platform reliability, availability, and protection of customer information.
Infrastructure security measures may include:
- Network segmentation and isolation
- Firewall and access control configurations
- Infrastructure monitoring and alerting
- Secure deployment and configuration management
- Environment separation between development, testing, and production systems
Application Security
Security considerations are incorporated throughout the software development lifecycle.
Our development and release processes may include:
- Secure coding practices
- Code review procedures
- Dependency and vulnerability monitoring
- Security testing before deployment
- Ongoing maintenance and updates
Backup and Recovery
We maintain backup and recovery procedures designed to support business continuity and data availability.
Backup processes may include:
- Scheduled backups
- Recovery testing
- Disaster recovery planning
- Infrastructure redundancy where appropriate
Vulnerability Management
Candor works to identify, assess, and remediate security vulnerabilities through ongoing monitoring and security reviews.
Security activities may include:
- Software updates and patch management
- Vulnerability assessments
- Security testing
- Infrastructure monitoring
- Risk evaluation and remediation
Security Incident Response
Candor maintains procedures for investigating, managing, and responding to security incidents.
When appropriate and required by applicable law, affected customers will be notified of confirmed incidents involving their personal information or customer data.
Service Availability
Candor is committed to maintaining a reliable and available platform.
Our operational practices may include:
- Platform monitoring
- Incident management procedures
- Backup and recovery processes
- Planned maintenance management
- Availability and performance monitoring
Responsible Disclosure
If you believe you have identified a security vulnerability affecting the Candor, please report it responsibly.
Please include:
- Description of the issue
- Steps to reproduce the issue
- Potential impact
- Supporting screenshots or logs, if available
Candor will review legitimate reports and take appropriate action to investigate and address verified security concerns.
Customer Responsibilities
Customers are responsible for:
- Protecting account credentials
- Managing user access permissions
- Maintaining endpoint and device security
- Reviewing platform-generated outputs before production use
- Maintaining appropriate security practices within their own environments
Security Certifications
Candor continuously evaluates its security controls and operational practices.
While Candor may align its security practices with industry standards and best practices, any certifications, audits, or compliance attestations will be disclosed separately when applicable.
Contact
For security-related questions or to report a potential security concern, please contact:
Email: support@candorsys.com
For general support inquiries, please use our Contact Us page or email the support team.