Security Statement
Calibrum is committed to protecting customer data and maintaining reliable safeguards for Surveylet and related services.
Security Statement
Last updated: August 4, 2026
Encrypted transmission
Calibrum uses Transport Layer Security (TLS/HTTPS) to protect data transmitted between supported browsers and the Services.
Protected infrastructure
Calibrum uses layered safeguards, access controls, monitoring, backups, and third-party infrastructure providers to support the Services.
Risk-based safeguards
Security measures are reviewed and adjusted based on the nature of the Services, Customer Data, and reasonably foreseeable risks.
Calibrum Inc. is committed to protecting Customer Data and maintaining reasonable administrative, technical, and organizational safeguards for Surveylet and related services. This statement summarizes Calibrum’s general security practices. Specific contractual commitments, if any, are governed by the applicable agreement.
SECURITY PROGRAM
Calibrum maintains a risk-based security program designed to protect the confidentiality, integrity, and availability of Customer Data. Safeguards may include documented policies and procedures, personnel controls, access restrictions, technical protections, monitoring, backup processes, vulnerability management, and incident-response procedures.
No information system can be guaranteed to be completely secure. Calibrum evaluates and updates safeguards as reasonably appropriate in light of changes in technology, threats, business operations, and applicable contractual or legal requirements.
ENCRYPTION AND TRANSMISSION
Calibrum uses Transport Layer Security (TLS), commonly displayed as HTTPS, to protect data transmitted between supported web browsers and the Services. Customer Data stored through the Services are protected using encryption at rest within the applicable hosting environment.
Customers are responsible for using supported browsers, protecting account credentials, maintaining secure devices and networks, and avoiding transmission of passwords or sensitive information through insecure channels.
ACCESS CONTROL
Access to production systems and Customer Data is limited to authorized personnel and service providers with a legitimate business need. Calibrum applies role-based or otherwise appropriate access controls and seeks to follow least-privilege principles.
Calibrum personnel do not routinely review Customer Data. Access may occur when reasonably necessary to provide support, maintain or secure the Services, investigate misuse, comply with legal obligations, or perform other authorized service activities. Customer authorization may be required for support access where supported by the Services or applicable agreement.
HOSTING AND INFRASTRUCTURE
Calibrum uses third-party hosting, infrastructure, and service providers to operate the Services. Providers are selected based in part on their security capabilities and are subject to contractual obligations appropriate to the services they provide.
Calibrum uses layered network and application protections, which may include firewalls, segmentation, logging, monitoring, anti-malware controls, rate limiting, and other safeguards appropriate to the environment.
VULNERABILITY MANAGEMENT AND TESTING
Calibrum conducts vulnerability management activities designed to identify, assess, prioritize, and remediate security weaknesses. These activities may include automated scanning, software and dependency updates, code or configuration review, and periodic penetration or security testing.
Customers may not conduct vulnerability scans, penetration tests, or other security testing against the Services without Calibrum’s prior written authorization.
BACKUPS, AVAILABILITY, AND RECOVERY
Calibrum maintains backup and recovery procedures designed to support service restoration and protect against data loss. The frequency, retention, and recovery characteristics of backups may vary based on the applicable system, service, and operational requirements.
Calibrum uses redundancy and recovery measures appropriate to the Services, but does not guarantee uninterrupted operation or that every event will be recoverable without data loss. Customers remain responsible for retaining exports or independent copies of Customer Data when required for their business, legal, or research needs.
DATA RETENTION AND DISPOSAL
Customer Data are retained and deleted according to the applicable agreement, customer instructions, operational requirements, and legal obligations. Storage media and infrastructure resources are disposed of or sanitized through documented provider or Calibrum procedures designed to prevent unauthorized recovery of data.
SECURITY INCIDENT RESPONSE
Calibrum maintains procedures for assessing and responding to suspected security incidents. Where a confirmed incident affects Customer Data and notification is required by applicable law or contract, Calibrum will notify affected customers in accordance with those requirements and provide reasonably available information about the incident and response.
HIPAA AND REGULATED DATA
Customers may not use the Services to collect, store, or process protected health information subject to HIPAA unless Calibrum has expressly agreed in writing and a Business Associate Agreement has been executed. A Business Associate Agreement applies only to the services, configurations, and uses expressly covered by that agreement.
Calibrum’s general security practices may be informed by recognized security principles and frameworks. Unless Calibrum expressly agrees otherwise in writing, this Security Statement does not represent that the Services are certified, authorized, or independently assessed under FISMA, FedRAMP, FIPS, SOC 2, ISO 27001, HITECH, or any other specific governmental or industry certification framework.
CUSTOMER RESPONSIBILITIES
Security is a shared responsibility. Customers are responsible for:
- maintaining accurate account information and limiting accounts to authorized users;
- using strong, unique passwords and available authentication safeguards;
- promptly disabling access for users who no longer require it;
- configuring surveys, permissions, invitations, exports, and integrations appropriately;
- complying with applicable privacy, security, research, and records-management requirements; and
- promptly reporting suspected unauthorized access or security issues to Calibrum.
SECURITY CONTACT
Questions about this Security Statement or reports of suspected security issues may be sent to support@calibrum.com or submitted through the Calibrum contact page.
