Security Statement
Candour maintains a security-first posture, adhering to industry standards for data handling and system integrity. This page outlines our current security practices.
Encryption
All data is encrypted at rest and in transit. We use TLS 1.3 for data in transit and industry-standard encryption for data at rest. API keys and credentials are stored using encrypted vault mechanisms.
Access Controls
Access to production systems is restricted to authorized personnel only. We enforce multi-factor authentication for all administrative access and maintain detailed audit logs of system access.
Data Handling
We process customer data solely for the purpose of delivering our services. We do not train AI models on customer data without explicit consent. Data retention follows the schedules outlined in our Data Processing Agreement.
Incident Response
We maintain an incident response plan and will notify affected customers promptly in the event of a security incident that impacts their data. Contact us at security@candour-partners.com to report vulnerabilities.
Third-Party Integrations
When you connect third-party services (CRM, dialer, enrichment tools), we access data via official APIs using your credentials. We recommend using scoped API keys with the minimum permissions necessary.