Security and compliance at Cal.com
Everything you need to evaluate Cal.com as a vendor. Our certifications and controls are public. Audit reports are available once you accept our non-disclosure agreement, which takes about a minute.
Documents
Certification
Report
Policy
Legal
Controls
213 controls across 22 areas, each mapped to the frameworks we are audited against. Open an area to see what it covers.
DCF-10 · ISO/IEC 27001:2022: A.5.15, A.6.7 · SOC 2: CC6.2, CC6.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(3)(ii)(A), 164.308(a)(3)(ii)(B), 164.308(a)(3)(ii)(C), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1), 164.312(d), 164.316(a), 164.316(b)(1)(i), 164.316(b)(1)(ii)
Cal.com has developed and documented a policy that outlines requirements for access control.
DCF-11 · ISO/IEC 27001:2022: A.5.16, A.5.18, A.8.2 · SOC 2: CC4.1, CC6.2, CC6.3, CC6.4 · HIPAA: 164.306(e), 164.308(a)(3)-(4), 164.312(a)(1), 164.316(b)(1)
Management performs user access reviews periodically to validate user accounts, including third party or vendor accounts, and their associated privileges remain appropriate. The review includes validation of logical and physical access as necessary. Changes resulting from the review, if any, are documented and implemented.
DCF-59 · ISO/IEC 27001:2022: A.8.2, A.8.3 · SOC 2: CC5.2, CC6.1 · HIPAA: 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1)
Administrative or privileged access to systems, resources, and functions is restricted to authorized personnel.
DCF-62 · ISO/IEC 27001:2022: A.8.5 · SOC 2: CC6.6 · HIPAA: 164.312(a)(2)(iii)
Cal.com's systems automatically terminate a user's logical session based on predefined conditions (e.g., predefined periods of inactivity, closure of the system or internet browser, etc.).
DCF-68 · ISO/IEC 27001:2022: A.5.17, A.8.5 · SOC 2: CC6.1, CC6.6 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(5)(ii)(D), 164.312(a)(2)(iii), 164.316(a)
Cal.com has a documented policy outlining the minimum requirements for passwords used for authentication to organizational systems. Password requirements are enforced for all systems in accordance with company policy.
DCF-69 · ISO/IEC 27001:2022: A.5.3, A.5.15, A.5.16, A.5.18, A.8.2, A.8.3 · SOC 2: CC5.1, CC5.2, CC6.1, CC6.2, CC6.3 · HIPAA: 164.308(a)(3)(ii)(A), 164.308(a)(3)(ii)(B), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1)
Access requests to information resources, including physical access and access to systems and data, are documented and approved by management based on least privilege, need to know, and segregation of duties principles.
DCF-70 · ISO/IEC 27001:2022: A.5.16, A.5.18 · SOC 2: CC6.1, CC6.2, CC6.3 · HIPAA: 164.308(a)(3)(ii)(C), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1)
System and physical access is revoked within one business day of effective termination date for terminated users (including employees, third parties and vendors, and other personnel).
DCF-72 · ISO/IEC 27001:2022: A.5.16 · SOC 2: CC6.1 · HIPAA: 164.312(a)(2)(i)
Root password authentication to production resources (e.g., virtual machines, containers, etc.) is disabled and only allowed for under exceptional circumstances for a limited time duration based on documented business justification and approval from management.
DCF-229 · ISO/IEC 27001:2022: A.5.17
All vendor-supplied default accounts are either disabled or removed, or their default password is changed in accordance with the company's policy and compliance requirements.
DCF-326 · ISO/IEC 27001:2022: A.8.2, A.8.3 · SOC 2: CC6.1
Cal.com restricts access to system components and data to only those individuals whose job requires such access.
DCF-350 · ISO/IEC 27001:2022: A.5.17 · SOC 2: CC6.1
System configuration settings are in place to prevent password reuse in accordance with company policy and compliance requirements.
DCF-356 · ISO/IEC 27001:2022: A.5.17, A.8.5 · SOC 2: CC6.1
Cal.com has documented policies and procedures for authentication that are communicated to all personnel. These documents include guidance on selecting strong authentication factors, guidance on protecting authentication credentials, instructions not to reuse previously used credentials, instructions to change authentication credentials in the event of known or suspected compromise along with guidance on how to report the incident, etc.
DCF-557 · ISO/IEC 27001:2022: A.5.16, A.8.2 · SOC 2: CC6.1
Group, shared, or generic account usage is prevented unless strictly necessary and supported by documented business justification and management approval. Mechanisms are in place to confirm individual user identity before access to the account is granted and to trace every action to an individual user.
DCF-562 · ISO/IEC 27001:2022: A.8.18 · SOC 2: CC6.8
Access to manage utility programs (including anti-virus consoles and diagnostic, patching, backup, or network tools, or any other utility can be capable of overriding system and application controls) is restricted to authorized system administrators. Standard users cannot disable privileged utilities or modify their configurations.
DCF-611 · ISO/IEC 27001:2022: A.8.5
Cal.com has implemented mechanisms to obscure the feedback of authentication information, such as usernames/passwords, during the authentication process where technically feasible (e.g., in company-developed systems or applications, configurable third-party systems, etc.).
DCF-781 · ISO/IEC 27001:2022: A.8.5 · SOC 2: CC3.3
Cal.com has implemented secure login procedures for in-house developed systems to deter enumeration or brute-force attacks (e.g., displaying limited information in login error messages without indicating which data is correct or incorrect, etc.)
DCF-783 · ISO/IEC 27001:2022: A.5.17 · SOC 2: CC6.1
Cal.com has implemented processes to change credentials (secrets, access keys, API keys, etc.) periodically based on a defined schedule.
DCF-2 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1), 164.316(a)
Cal.com authorizes access to information resources, including data and the systems that store or process sensitive data, based on the principle of least privilege.
DCF-58 · HIPAA: 164.312(a)(2)(i), 164.312(c)(1), 164.312(e)(2)(i)
Cal.com has implemented systems or mechanisms to centralize authentication and account management across the organization (e.g., directory service, identity provider, etc.).
DCF-60 · SOC 2: CC6.1 · HIPAA: 164.308(a)(5)(ii)(D)
Cal.com has implemented technical measures to protect stored user passwords for the system (e.g., encryption, hashing, salting, etc.).
DCF-339 · SOC 2: CC6.1
Invalid authentication attempts are limited by locking out the user ID after not more than 10 failed attempts.
DCF-340 · SOC 2: CC6.1
Cal.com has configured account lockout duration following a set number of invalid authentication attempts to a minimum of 30 minutes or until the identity of the user is confirmed (for example, by a system administrator).
DCF-355 · SOC 2: CC6.6
All remote access to the entity's network and systems (including that of users, administrators, and external access from third parties or vendors including access for maintenance sessions) requires multi-factor authentication.
DCF-20 · ISO/IEC 27001:2022: A.5.9 · SOC 2: CC2.1, CC6.1 · HIPAA: 164.310(d)(2)(iii)
A centralized asset register is maintained for physical, cloud, and other assets that includes descriptive attributes for asset accountability such as owner, description, location, classification, and/or other information based on the type of asset. Processes are in place to maintain an updated inventory through manual reviews (e.g., as a result of new purchases, installations, removals, system changes, etc.) or automated mechanisms.
DCF-182 · ISO/IEC 27001:2022: A.6.7, A.8.1 · SOC 2: CC5.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.310(d)(1), 164.310(d)(2)(i), 164.310(d)(2)(ii), 164.310(d)(2)(iii), 164.316(a)
Cal.com has established and documented a policy that outlines requirements for the management and tracking of company assets.
DCF-569 · ISO/IEC 27001:2022: A.5.13
Cal.com has developed and implemented procedures for labeling of assets and information across the organization in accordance with the organization's information classification scheme.
DCF-777 · ISO/IEC 27001:2022: A.5.9, A.5.12 · SOC 2: CC6.1
Cal.com uses tags to assign metadata to cloud resources to facilitate identification, inventory, and classification of virtual assets.
DCF-25 · ISO/IEC 27001:2022: A.5.29, A.5.30 · SOC 2: CC5.3, CC9.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C), 164.310(a)(2)(i), 164.310(d)(2)(iv), 164.312(a)(2)(ii), 164.316(a)
Cal.com has a documented disaster recovery plan that outlines roles, responsibilities and detailed procedures for recovery of systems in the event of a disaster scenario.
DCF-26 · ISO/IEC 27001:2022: A.5.30 · HIPAA: 164.308(a)(7)(i), 164.308(a)(7)(ii)(D), 164.312(a)(2)(ii)
Cal.com conducts tests of the business continuity/disaster recovery plans at least annually. Results and lessons learned are documented, and updates to the plans are made as necessary.
DCF-100 · ISO/IEC 27001:2022: A.8.13 · HIPAA: 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
Cal.com tests the integrity and recoverability of backed-up data at least annually.
DCF-166 · ISO/IEC 27001:2022: A.5.29, A.5.30 · SOC 2: CC5.3, CC9.1 · HIPAA: 164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C), 164.310(a)(2)(i), 164.312(a)(2)(ii)
Cal.com has a defined business continuity plan that outlines strategies for maintaining operations during a disruption.
DCF-169 · ISO/IEC 27001:2022: A.8.13 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv), 164.316(a)
Cal.com has defined and documented a backup policy that establishes the requirements for backup information, software and systems.
DCF-684 · ISO/IEC 27001:2022: A.8.14
Cal.com has implemented redundancy strategies for equipment, systems, and processes as deemed necessary per the business continuity plan(s) to meet availability requirements (e.g., redundancy in network components, production resources, supporting utilities, service providers, processing sites, etc.)
DCF-98 · HIPAA: 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv), 164.312(b), 164.312(c)(2)
Backups are encrypted and segmented from production systems (e.g., air-gapped, replicated to a different region, stored offsite, etc.) to ensure protection from a disaster or incident.
DCF-5 · ISO/IEC 27001:2022: A.5.3 · SOC 2: CC8.1
Changes are peer-reviewed and approved prior to deployment by an individual different from the developer to maintain segregation of duties. Review requirements are enforced through automated mechanisms such as branch protection settings in the production code repository.
DCF-6 · ISO/IEC 27001:2022: A.8.4, A.8.31 · SOC 2: CC5.1, CC8.1
Access to make changes in production environments is restricted to authorized personnel in accordance with segregation of duties principles and the company's documented policies and procedures.
DCF-7 · ISO/IEC 27001:2022: A.8.31 · SOC 2: CC8.1
Pre-production environments (e.g., development, testing, etc.) are separated from production environments and the separation is enforced with access controls.
DCF-76 · ISO/IEC 27001:2022: A.8.32 · SOC 2: CC8.1
Emergency changes or hot fixes implemented outside of the standard change management process are reviewed and approved by an authorized individual after implementation.
DCF-155 · ISO/IEC 27001:2022: A.8.19, A.8.29, A.8.31 · SOC 2: CC8.1
Changes are tested in an environment separate from production prior to deployment in accordance with the nature of the change. Documented evidence of testing criteria and testing results is retained.
DCF-156 · ISO/IEC 27001:2022: A.8.32 · SOC 2: CC8.1
Change releases are approved by authorized personnel prior to deployment to production.
DCF-305 · ISO/IEC 27001:2022: A.5.8, A.8.19, A.8.26, A.8.32 · SOC 2: CC5.2, CC6.8, CC8.1
Changes to all system components in the production environment (including software, code, infrastructure, network, configuration changes, etc.) are made according to established procedures that include documentation (change description, justification, evaluation of security requirements and impact, approval by authorized parties, rollback procedures, etc.) and testing (including acceptance and security impact testing).
DCF-567 · ISO/IEC 27001:2022: A.5.8, A.8.32 · SOC 2: CC8.1
Cal.com has a documented a policy that describes the requirements for managing changes across the organization, including changes to infrastructure, systems, and applications.
DCF-74 · SOC 2: CC2.3
Cal.com communicates system changes via release notes or change log in the company's website or via periodic communications.
DCF-12 · ISO/IEC 27001:2022: A.8.9 · SOC 2: CC6.1, CC7.1 · HIPAA: 164.308(a)(4)(ii)(A)
Cal.com has identified and documented baseline security configuration standards for all system components in accordance with industry-accepted hardening standards or vendor recommendations. These standards are reviewed periodically and updated as needed (e.g., when vulnerabilities are identified) and verified to be in place before or immediately after a production system component is installed or modified (e.g., through infrastructure as code, configuration checklists, etc.).
DCF-45 · ISO/IEC 27001:2022: 7.5.3, A.5.33 · SOC 2: CC6.7 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(5)(ii)(C), 164.312(c)(1), 164.312(c)(2), 164.312(e)(2)(i), 164.312(e)(2)(ii), 164.316(a), 164.316(b)(2)(i)
Cal.com has a documented a policy that outlines the procedures and technical measures to be implemented at the organization to protect the confidentiality, integrity, and availability of data.
DCF-101 · ISO/IEC 27001:2022: 7.5.3, A.5.14, A.5.33 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a), 164.316(b)(2)(i)
Cal.com has a documented and implemented a policy for data retention defining the types of data (including company and customer data) and the period of time for which they should be retained.
DCF-102 · ISO/IEC 27001:2022: 7.5.3, A.5.12, A.5.13, A.5.33, A.8.24 · SOC 2: CC2.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com has established a data classification policy in order to identify the types of information stored or processed by the organization and the protection measures that are required for each.
DCF-103 · ISO/IEC 27001:2022: A.8.10 · HIPAA: 164.316(b)(2)(i)
Cal.com disposes of customer data upon termination of services in accordance with contractual agreements.
DCF-123 · ISO/IEC 27001:2022: A.8.10 · SOC 2: CC6.5 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com has documented policies and procedures for erasure or destruction of information that has been identified for disposal.
DCF-150 · ISO/IEC 27001:2022: A.5.14, A.8.12, A.8.16 · SOC 2: CC6.7 · HIPAA: 164.312(a)(2)(iv), 164.312(e)(1)
Cal.com has implemented data leakage prevention mechanisms to systems that could process, store or transmit sensitive information (e.g., sending personal information via email). These mechanisms are configured to prevent data leakage and generate audit logs and alerts.
DCF-180 · ISO/IEC 27001:2022: A.5.14
Cal.com has defined and documented policies and procedures for the secure transfer of information within the organization and with any external parties.
DCF-253 · ISO/IEC 27001:2022: A.5.14, A.8.10
Cal.com disposes of data securely upon expiration of the established retention periods, when requested by customers, or when no longer needed for legal, regulatory, and/or business reasons.
DCF-1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com Management has approved all policies that detail how customer data may be made accessible and should be handled. These policies are accessible to all employees and contractors.
DCF-61 · SOC 2: CC6.1
Cal.com has implemented segregation mechanisms so that customers cannot impact or access data or resources of other customers.
DCF-197 · HIPAA: 164.316(b)(2)(i), 164.520(e), 164.522(a)(3), 164.530(j)
Cal.com retains HIPAA-related policies and procedures for at least 6 years from the date of the document's creation or when it was last in effect (whichever is later).
DCF-54 · ISO/IEC 27001:2022: A.5.33, A.8.24 · SOC 2: CC6.1, CC6.6 · HIPAA: 164.312(a)(2)(iv), 164.312(e)(2)(ii)
Data at rest is encrypted using strong cryptographic algorithms.
DCF-55 · ISO/IEC 27001:2022: A.5.14, A.8.24 · SOC 2: CC6.1, CC6.6, CC6.7 · HIPAA: 164.312(a)(2)(iv), 164.312(e)(1)
Data in transit is encrypted using strong cryptographic algorithms.
DCF-149 · ISO/IEC 27001:2022: A.7.10 · SOC 2: CC6.7 · HIPAA: 164.312(a)(2)(iv)
Cal.com encrypts removable media devices, such as USB drives, digital video disks, compact disks, external or removable hard disks, etc., that contain sensitive data, to protect the confidentiality of the information during transport.
DCF-181 · ISO/IEC 27001:2022: A.8.24 · SOC 2: CC5.3, CC6.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.312(a)(2)(iv), 164.312(c)(1), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii), 164.316(a)
Cal.com has a documented policy that establishes requirements for the use of cryptographic controls.
DCF-273 · ISO/IEC 27001:2022: A.8.24 · SOC 2: CC6.1
Key-management policies and procedures are documented and implemented including: generation of strong cryptographic keys, secure distribution, and secure storage of cryptographic keys used to protect sensitive data.
DCF-284 · ISO/IEC 27001:2022: A.8.24
Cal.com has implemented security mechanisms so that only trusted keys and/or certificates are accepted during transmission of sensitive data that are confirmed valid and not expired or revoked.
DCF-779 · ISO/IEC 27001:2022: A.8.24 · SOC 2: CC6.1
Cal.com has implemented processes to change cryptographic keys periodically based on a defined schedule.
DCF-3 · HIPAA: 164.312(a)(2)(iv), 164.312(e)(1)
Administrator access to web-based management interfaces is encrypted with strong cryptographic algorithms.
DCF-53 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com has an established policy and procedures that governs the use of cryptographic controls.
DCF-93 · HIPAA: 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.312(a)(1), 164.312(a)(2)(iv)
Cal.com has an established key management process in place to support the organization's use of cryptographic techniques.
DCF-278 · SOC 2: CC6.1
Cal.com retires, replaces or destructs cryptographic keys that are no longer used or needed or when the key expires, the integrity of the key has been weakened, or the key is known or suspected to be compromised, in accordance with documented company policies and procedures. Retired or replaced keys are not used for encryption operations.
DCF-293 · ISO/IEC 27001:2022: A.8.7 · SOC 2: CC6.8
The deployed anti-malware solution is kept current via automatic updates and configured to detect all known types of malware and to remove, block, or contain all known types of malware.
DCF-294 · ISO/IEC 27001:2022: A.8.7 · SOC 2: CC6.8
The implemented anti-malware solutions are configured to perform periodic scans and active/real-time scans (e.g., scanning files from external sources as they are downloaded, opened, or executed) or to perform continuous behavioral analysis of systems or processes.
DCF-558 · ISO/IEC 27001:2022: A.5.32, A.8.7, A.8.19 · SOC 2: CC6.8
Cal.com has identified allowed software programs in the organization and implemented mechanisms to restrict and monitor the installation and execution of unauthorized software (e.g., through procedural methods or automated mechanisms such as corporate app stores and deny-all, allow-by-exception rules). The list of allowed software is reviewed and updated periodically as determined by the organization.
DCF-574 · ISO/IEC 27001:2022: A.6.7, A.7.9, A.8.1 · SOC 2: CC6.4, CC6.5, CC6.8
A mobile device management (MDM) is installed in company-issued devices and bring-your-own devices used for company purposes to enforce security for assets off-premise (e.g., location tracking, remote locking and wiping, threat detection, restrictions on software installation, etc.)
DCF-522 · SOC 2: CC6.8
The implemented anti-malware solutions are configured to perform automatic scans or continuous behavioral analysis of systems or processes when removable electronic media is inserted, connected, or logically mounted within the environment.
DCF-28 · ISO/IEC 27001:2022: A.5.25, A.5.26 · SOC 2: CC7.3, CC7.4, CC7.5 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com evaluates security events to determine if they constitute an incident. Incidents are assigned a priority, categorized, documented, tracked, escalated, contained, eradicated, communicated, and resolved in accordance with company policies and procedures.
DCF-29 · ISO/IEC 27001:2022: A.5.24 · SOC 2: CC7.3, CC7.4, CC7.5 · HIPAA: 164.308(a)(6)(i), 164.308(a)(6)(ii)
Cal.com has identified and documented roles and responsibilities for incident management (e.g., roles and responsibilities for invoking the incident management process, incident leads, incident handlers, communication coordinators, technical advisors, legal advisors, etc.).
DCF-30 · ISO/IEC 27001:2022: A.5.26, A.5.27, A.5.28 · SOC 2: CC7.3, CC7.4, CC7.5
Cal.com documents a post-mortem review for identified incidents that includes incident metadata, root-cause analysis, documentation of evidence, summary of containment, eradication, and recovery actions, timelines, incident metrics, evidence of internal and external communications, estimation of impact and scope, and lessons learned, as applicable, in accordance with company policies and procedures.
DCF-135 · ISO/IEC 27001:2022: A.5.5, A.5.26 · SOC 2: CC7.3, CC7.4, CC7.5 · HIPAA: 164.402, 164.404(a), 164.404(b), 164.404(c), 164.404(d), 164.406, 164.408, 164.410, 164.412, 164.414(a), 164.414(b)
Cal.com provides communications about breaches and incidents to affected parties, organizational officials, authorities, and other internal and external stakeholders, in accordance with company policies and procedures and contractual and legal obligations.
DCF-154 · ISO/IEC 27001:2022: A.5.24 · SOC 2: CC7.3, CC7.4, CC7.5 · HIPAA: 164.308(a)(6)(i), 164.308(a)(6)(ii)
Cal.com performs a test of all components of the incident response plan and procedures at least annually through different mechanisms (e.g., walk-through or tabletop exercises, simulations, etc.). The documented plan and procedures are updated if necessary based on the results of the test.
DCF-159 · ISO/IEC 27001:2022: A.5.24 · SOC 2: CC7.3, CC7.4, CC7.5, CC9.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(6)(i), 164.308(a)(6)(ii), 164.316(a), 164.402
Cal.com has a documented an incident response plan that outlines roles, responsibilities, and procedures to document, analyze, categorize, and respond to incidents. The incident response plan reviewed periodically and updated as needed according to lessons learned from previous incidents and industry developments.
DCF-689 · ISO/IEC 27001:2022: A.5.24 · SOC 2: CC7.3, CC7.4, CC7.5
Specific personnel are designated to be available on a 24/7 basis to respond to suspected or confirmed security incidents and operational issues through an on-call rotation schedule.
DCF-131 · HIPAA: 164.308(a)(6)(i), 164.308(a)(6)(ii)
Cal.com has incident management procedures that include detailed instructions on how to escalate a suspected incident to the Information Security Team and, when necessary, to the Privacy or Legal department. Cal.com has a standard incident report template that must be completed for each incident.
DCF-193 · HIPAA: 164.402, 164.404(a), 164.404(b), 164.404(c), 164.404(d), 164.406, 164.408, 164.410, 164.412, 164.414(a), 164.414(b)
Cal.com information security policies should be augmented by a statement concerning support for and commitment to achieving compliance with applicable PII protection legislation and the contractual terms agreed between the public cloud PII processor and its clients (cloud service customers).
DCF-27 · ISO/IEC 27001:2022: A.8.14 · SOC 2: CC9.1 · HIPAA: 164.308(a)(7)(i), 164.308(a)(7)(ii)(A), 164.310(a)(2)(i), 164.310(d)(2)(iv), 164.312(a)(2)(ii)
Business-critical cloud resources are deployed in accordance with high availability architecture principles (e.g., replicated across multiple availability zones or regions, configured for high-availability, etc.).
DCF-78 · ISO/IEC 27001:2022: A.5.33, A.8.13 · SOC 2: CC7.1
Storage buckets that contain sensitive data have versioning enabled to preserve, retrieve, and restore versions of objects.
DCF-96 · ISO/IEC 27001:2022: A.8.6, A.8.14
Cal.com uses a load balancer to automatically distribute incoming traffic across multiple targets.
DCF-97 · ISO/IEC 27001:2022: A.8.6
Cal.com has enabled auto-scaling configurations to provision new cloud resources when predefined capacity thresholds are met.
DCF-775 · ISO/IEC 27001:2022: A.5.33
Cal.com has enabled deletion protection for cloud resources to prevent irreversible data loss or downtime resulting from accidental or malicious actions.
DCF-79 · ISO/IEC 27001:2022: A.8.15, A.8.16 · SOC 2: CC7.2 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com uses a centralized system that collects and stores logs of system activity and sends alerts to personnel based on pre-configured rules. Access to logs is restricted to authorized personnel.
DCF-86 · ISO/IEC 27001:2022: A.8.16 · SOC 2: CC4.1, CC7.1, CC7.2 · HIPAA: 164.308(a)(8)
Production systems and resources are monitored and automated alerts are sent out personnel based on pre-configured rules. Events are triaged to determine if they constitute an incident and escalated per policy if necessary.
DCF-90 · ISO/IEC 27001:2022: A.8.2, A.8.16 · SOC 2: CC6.1, CC7.2
Access to the root account in the cloud infrastructure provider is monitored. Login activity for the root account is investigated and validated for appropriateness.
DCF-406 · ISO/IEC 27001:2022: A.8.16 · SOC 2: CC7.2
Audit logs are enabled and active for all system components and sensitive data in accordance with company policies.
DCF-407 · ISO/IEC 27001:2022: A.8.15, A.8.16 · SOC 2: CC7.2
Cal.com has configured audit logs to contain user or identity, type of event, date and time, success and failure indication, origination of event, affected data, and system component, resource, or service.
DCF-409 · ISO/IEC 27001:2022: A.8.15, A.8.16 · SOC 2: CC7.2
Automated audit trails or logs are implemented for all system components to capture all actions taken by any identities with administrative access, including execution of privileged functions and any interactive use of application or system accounts.
DCF-411 · ISO/IEC 27001:2022: A.8.16 · SOC 2: CC7.2
Automated audit trails or logs are implemented for all system components to capture all invalid access attempts.
DCF-412 · ISO/IEC 27001:2022: A.5.16, A.8.16 · SOC 2: CC7.2
Automated audit trails or logs are implemented to capture all changes to identification and authentication credentials (e.g., creation of new accounts, elevation of privileges, changes, additions, or deletions to accounts with administrative access, etc.).
DCF-414 · ISO/IEC 27001:2022: A.8.16 · SOC 2: CC7.2
Automated audit trails or logs are implemented for all system components to capture all creation and deletion of system-level objects.
DCF-430 · ISO/IEC 27001:2022: A.8.15
Audit log files are protected to prevent modifications by individuals (e.g., via access control mechanisms, physical segregation, network segregation, etc.)
DCF-434 · ISO/IEC 27001:2022: A.8.15
Cal.com has documented policies and procedures for logging and monitoring that describe the events the organization must log and monitor, the general systems and system components that should be monitored, the specific information that must be captured in logs, the configuration of specific elements of the logging infrastructure, etc. The identified logged/monitored events are reviewed and updated periodically in accordance with company requirements.
DCF-478 · ISO/IEC 27001:2022: A.8.15 · SOC 2: CC6.8, CC7.1, CC8.1
Cal.com has enabled file integrity monitoring or a change-detection mechanism to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, audit files, or content files to ensure critical data cannot be changed without generating alerts.
DCF-698 · ISO/IEC 27001:2022: A.8.15
Cal.com has implemented automated mechanisms for audit record reduction that supports correlated audit log review and analysis, such as centralized log management systems, event log analyzers, security information and event management (SIEM) solutions, etc.
DCF-741 · ISO/IEC 27001:2022: A.8.15, A.8.16 · SOC 2: CC7.2
Cal.com has a documented policy that outlines requirements for audit logging and monitoring of system activity at the company.
DCF-80 · HIPAA: 164.308(a)(5)(ii)(C), 164.312(b), 164.312(c)(2)
Cal.com uses logging software that sends alerts to appropriate personnel. Corrective actions are performed, as necessary, in a timely manner.
DCF-81 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com has implemented tools to monitor Cal.com's databases and notify appropriate personnel of any events or incidents based on predetermined criteria. Incidents are escalated per policy.
DCF-82 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com has implemented tools to monitor Cal.com's messaging queues and notify appropriate personnel of any events or incidents based on predetermined criteria. Incidents are escalated per policy.
DCF-83 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com has implemented tools to monitor Cal.com's NoSQL databases and notify appropriate personnel of any events or incidents based on predetermined criteria. Incidents are escalated per policy.
DCF-84 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com has implemented tools to monitor Cal.com's servers and notify appropriate personnel of any events or incidents based on predetermined criteria. Incidents are escalated per policy.
DCF-151 · HIPAA: 164.312(c)(1), 164.312(c)(2)
Cal.com ensures that file integrity monitoring (FIM) software is in place to detect whether operating system and application software files have been tampered with.
DCF-177 · HIPAA: 164.308(a)(5)(ii)(C), 164.312(b), 164.312(c)(2)
Cal.com has a defined plan for event logging that establishes the required criteria for logs, protection of logged information, clock synchronization.
DCF-189 · HIPAA: 164.308(a)(1)(ii)(D)
Cal.com performs a review of information system activities on regular intervals
DCF-22 · ISO/IEC 27001:2022: A.8.20, A.8.22 · SOC 2: CC2.1 · HIPAA: 164.306(e), 164.316(b)(1)(i), 164.316(b)(1)(ii)
A documented network diagram is in place to document system boundaries and connections to external networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.
DCF-87 · ISO/IEC 27001:2022: A.8.16, A.8.21 · SOC 2: CC6.6, CC6.8, CC7.1, CC7.2 · HIPAA: 164.312(b), 164.312(c)(2)
A threat detection system is in place to monitor web traffic and suspicious activity. When anomalous traffic activity is identified, alerts are automatically sent to personnel, investigated, and escalated through the incident management process, if necessary.
DCF-88 · ISO/IEC 27001:2022: A.8.16 · SOC 2: CC6.6, CC7.2
A web application firewall is in place to protect public-facing web applications from outside threats.
DCF-91 · ISO/IEC 27001:2022: A.8.16, A.8.21 · SOC 2: CC6.6, CC7.1, CC7.2 · HIPAA: 164.308(a)(5)(ii)(B)
An intrusion detection system (IDS)/intrusion prevention system (IPS) or equivalent is in place to detect real-time suspicious or anomalous network traffic that may be indicative of threat actor activity and is configured to alert personnel when a potential intrusion is detected.
DCF-92 · ISO/IEC 27001:2022: A.6.7, A.8.21 · SOC 2: CC6.1, CC6.6 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.312(a)(2)(iv), 164.312(e)(1), 164.316(a)
Remote access to production systems is only available through an encrypted connection (e.g., encrypted virtual private network, SSH, etc.)
DCF-678 · ISO/IEC 27001:2022: A.8.20, A.8.21, A.8.22
Cal.com has defined and documented a policy that outlines requirements for deployment, management and operation of network security controls at the company.
DCF-687 · ISO/IEC 27001:2022: A.5.14
Cal.com has implemented processes and automated mechanisms to maintain the integrity of email communications and detect or protect against phishing attacks and malicious emails (e.g., DMARC, SPF and DKIM to prevent spoofed or modified emails from valid domains, etc.).
DCF-748 · ISO/IEC 27001:2022: A.8.21, A.8.22 · SOC 2: CC6.1, CC6.6
Cal.com uses network segmentation and/or other techniques to isolate portions of the environment and to control traffic between them based on security and business needs.
DCF-21 · SOC 2: CC2.1 · HIPAA: 164.308(a)(4)(ii)(A)
A documented architectural diagram is in place to document system boundaries and support the functioning of internal control. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.
DCF-204 · SOC 2: CC2.1
A dataflow diagram is maintained to show all account data flows across systems and networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.
DCF-9 · ISO/IEC 27001:2022: A.5.4, A.5.24, A.6.8 · SOC 2: CC1.1, CC1.5, CC2.2 · HIPAA: 164.402
Internal communication channels are in place for employees to report failures, events, incidents, policy violations, concerns, and other issues to company management, including anonymous reporting channels if applicable.
DCF-14 · ISO/IEC 27001:2022: 5.3, A.5.2 · SOC 2: CC1.3, CC1.5, CC2.2
An organizational chart is in place to describe the organizational structure and reporting lines. The chart is available to all employees (e.g., through the company's HRMS, intranets, etc.) and is updated upon changes to the organizational structure.
DCF-42 · ISO/IEC 27001:2022: 5.1, 5.3, A.5.2 · SOC 2: CC1.2, CC1.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Management has defined and documented roles and responsibilities for implementation and oversight of the risk management and compliance programs (e.g., security, privacy, AI, etc.).
DCF-8 · SOC 2: CC2.3 · HIPAA: 164.402
Cal.com provides external communication mechanisms for customers and third parties (e.g., communication features, support portal, external ticketing system, etc.) to report complaints, failures, bugs, incidents, vulnerabilities, requests for information, etc. Customer communications are responded to within defined SLAs.
DCF-34 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.316(a), 164.316(b)(1)(i), 164.316(b)(1)(ii), 164.316(b)(2)(ii)
Cal.com has an assigned security team that is responsible for the design, implementation, management, and review of the organization's security policies, standards, baselines, procedures, and guidelines.
DCF-35 · HIPAA: 164.316(a), 164.316(b)(1)(i), 164.316(b)(1)(ii), 164.316(b)(2)(ii)
The security team communicates important information security events to company management in a timely manner.
DCF-190 · HIPAA: 164.308(a)(2), 164.530(a)
Cal.com has formally assigned responsibility for information security in the organization to a Chief Information Security Officer or other security-knowledgeable member of management.
DCF-46 · ISO/IEC 27001:2022: 7.2, A.6.1 · SOC 2: CC1.4
Management evaluates candidates for employment through a formal screening process. The process may include verification of academic and professional qualifications, identity verifications, validation of personal or professional references, technical interviews, or other steps as deemed applicable by the organization.
DCF-47 · ISO/IEC 27001:2022: 5.3, A.5.2 · SOC 2: CC1.4, CC2.2
Cal.com has documented job descriptions for each position at the company, which include roles and responsibilities as well as required qualifications, skills, and experience for the role.
DCF-105 · ISO/IEC 27001:2022: A.6.2, A.6.5, A.6.6 · SOC 2: CC1.1, CC2.3
Personnel, including employees and contractors, are required to sign an agreement that outlines confidentiality requirements (e.g., non-disclosure agreements) prior to hire.
DCF-173 · ISO/IEC 27001:2022: 5.3, A.5.2, A.5.4, A.6.2, A.6.5 · SOC 2: CC1.1, CC1.3, CC2.2
Personnel responsibilities for information security (including confidentiality, legal, and data handling requirements), including responsibilities that remain after employment, are communicated to and acknowledged by personnel (e.g., through employment contracts, etc.)
DCF-570 · ISO/IEC 27001:2022: A.6.4 · SOC 2: CC1.1, CC1.5
Cal.com has a defined disciplinary sanctions process to be enacted when a member of the workforce violates the company's policies or causes a security or privacy incident. Management retains documentation of instances when the disciplinary process was enacted.
DCF-688 · ISO/IEC 27001:2022: A.5.11, A.6.5 · SOC 2: CC6.4
Cal.com tracks and documents the return of all electronic and physical assets upon termination as part of the offboarding process. Access mechanisms such as keys, access cards, MFA tokens, are disabled or collected by IT or HR personnel.
DCF-38 · SOC 2: CC1.1, CC1.4, CC1.5
Management conducts periodic evaluations of performance against established goals and objectives for eligible personnel in accordance with company policies and procedures.
DCF-43 · HIPAA: 164.308(a)(3)(ii)(A), 164.308(a)(3)(ii)(C), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(4)(ii)(C), 164.312(a)(1)
Cal.com uses a termination checklist to ensure that an employee's system access, including physical access, is removed within a specified timeframe and all organization assets (physical or electronic) are properly returned.
DCF-106 · ISO/IEC 27001:2022: A.5.14, A.7.7 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com has defined clear desk and clear screen policies and procedures to protect confidential data (physical and electronic) which are communicated to personnel and enforced across the organization.
DCF-107 · ISO/IEC 27001:2022: A.8.10 · SOC 2: CC6.5 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.310(d)(2)(i), 164.310(d)(2)(ii), 164.316(a)
When Cal.com disposes of hard copy materials, it does so through secure means such as cross-cut shredding, incinerating, or pulping, so that sensitive data cannot be reconstructed.
DCF-108 · ISO/IEC 27001:2022: A.7.7 · SOC 2: CC6.4 · HIPAA: 164.316(b)(2)(i)
Cal.com uses secure storage mechanisms for digital media and hardcopy materials that contain sensitive data (e.g., locked codes, combination locks to offices, rooms and facilities such as key cabinets, etc.) as well as critical equipment and other assets. Access to the secured storage mechanisms (including access to physical keys and knowledge of authentication information) is restricted to authorized personnel.
DCF-109 · ISO/IEC 27001:2022: A.7.14, A.8.10 · SOC 2: CC6.5 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.310(d)(2)(i), 164.310(d)(2)(ii), 164.316(a)
Cal.com disposes of data on hardware through secure means, such as wiping and hard drive destruction, in accordance with documented policies and procedures.
DCF-381 · ISO/IEC 27001:2022: A.7.10 · SOC 2: CC6.7
Media with sensitive data is physically secured to prevent unauthorized persons from gaining access to it.
DCF-384 · ISO/IEC 27001:2022: A.7.10
All media with sensitive data is classified in accordance with the nature of the data and the company's data classification policy.
DCF-390 · ISO/IEC 27001:2022: A.7.14
Electronic media is destroyed or sensitive data is rendered unrecoverable so that it cannot be reconstructed when no longer needed for business or legal reasons.
DCF-619 · ISO/IEC 27001:2022: A.7.14
Cal.com sanitizes equipment and system media that contain sensitive prior to disposal, release for reuse, or release out of organizational control (e.g., removed from premises for off-site maintenance). Cal.com reviews, approves, tracks, documents, and verifies media sanitization and disposal actions in accordance with company policies and procedures.
DCF-94 · SOC 2: CC6.4 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(c), 164.316(a)
Cal.com has a documented policy that outlines requirements for physical security.
DCF-147 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(b), 164.310(c), 164.312(a)(1), 164.316(a)
Cal.com has security policies that have been approved by management and detail how physical access to the company's headquarters is maintained. These policies are accessible to all employees and contractors.
DCF-363 · SOC 2: CC6.4
Entry controls (e.g., badge access systems, biometrics readers, monitored reception areas or front desks, etc.) are in place to restrict physical access to corporate facilities, including systems or areas that may process or store sensitive data, to authorized personnel, and to log and monitor such access.
DCF-365 · SOC 2: CC6.4
Cal.com physical surveillance mechanisms (e.g., video monitoring systems, sensors and detectors) are in place to deter and detect unauthorized physical access and are protected from tampering or disabling.
DCF-372 · SOC 2: CC6.4
Cal.com restricts access to the identification or badge system to authorized personnel based on need-to-know principles.
DCF-374 · SOC 2: CC6.4
Visitors are authorized before entering, and escorted at all times within company facilities including areas where sensitive data may be processed or stored.
DCF-375 · SOC 2: CC6.4
Cal.com personnel are required to wear a badge or other form of identification within company facilities. Cal.com provides visitors with a badge or other form of identification that visibly distinguishes visitors from onsite personnel.
DCF-377 · SOC 2: CC6.4
Visitor badges or identification are surrendered or deactivated before visitors leave the facility or at the date of expiration.
DCF-13 · ISO/IEC 27001:2022: 5.2, 7.3, A.5.1, A.6.8 · SOC 2: CC2.1, CC5.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(1)(ii)(C), 164.308(a)(2), 164.308(a)(5)(i), 164.308(a)(8), 164.310(b), 164.316(a)
Cal.com has defined and documented an information security policy and other topic-specific policies as needed to support the functioning of internal control.
DCF-33 · ISO/IEC 27001:2022: A.5.1, A.5.4 · SOC 2: CC2.1, CC2.2, CC5.3 · HIPAA: 164.306(e), 164.308(a)(8), 164.316(b)(1)(i), 164.316(b)(1)(ii), 164.316(b)(2)(iii)
Management reviews and approves company policies at least annually. Updates to the policies are made as deemed necessary (e.g., based on changes to business objectives, legal or regulatory requirements, organizational risks, etc.).
DCF-37 · ISO/IEC 27001:2022: A.5.10, A.5.14, A.5.32, A.6.7 · SOC 2: CC5.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(5)(ii)(B), 164.310(b), 164.316(a)
Cal.com has a documented acceptable use policy that outlines requirements for personnel's usage of company assets.
DCF-160 · ISO/IEC 27001:2022: 8.1, 9.1, A.5.36 · SOC 2: CC2.1, CC2.2, CC3.2, CC3.3, CC3.4, CC4.1, CC4.2, CC5.1, CC5.2 · HIPAA: 164.312(b), 164.312(c)(2)
Cal.com uses compliance automation software to identify, select, and continuously monitor internal controls.
DCF-161 · ISO/IEC 27001:2022: 4.1, 4.2, 4.3
Cal.com has documented the scope of its management system(s) that outlines the boundaries and applicability of the system(s) and considers internal and external issues, requirements of interested parties, and interfaces and dependencies with other organizations.
DCF-163 · ISO/IEC 27001:2022: 4.2, A.5.31
Cal.com has identified and documented the legal, statutory, regulatory and contractual requirements relevant to the organization. Cal.com has assigned responsibility and identified and implemented processes to satisfy these requirements and monitor and review changes.
DCF-170 · ISO/IEC 27001:2022: 5.1, 5.2, 6.2, 7.1, 8.1
Cal.com has documented objectives for its management system(s) (e.g., security objectives, privacy objectives, AI objectives, etc.) and plans to achieve them.
DCF-175 · ISO/IEC 27001:2022: 7.4, A.5.5
Cal.com has documented communication plans that establishes procedures for internal and external communications relevant to its information security, privacy, or other programs.
DCF-176 · ISO/IEC 27001:2022: 9.1
Cal.com has defined performance and/or effectiveness measurements for its management system(s) and implemented procedures to monitor these measurements periodically as determined by the organization.
DCF-178 · ISO/IEC 27001:2022: 7.5.1, 7.5.2, 7.5.3
Cal.com implemented procedures for the control of documented information relevant for its management system(s).
DCF-184 · ISO/IEC 27001:2022: 4.1, 4.3, 4.4, 5.1, 5.2, 5.3, 6.1.1, 6.2, 6.3, 7.1, 8.1, 9.1, 10.1, 10.2, A.5.2
Cal.com has a defined and documented a plan for the establishment, implementation, maintenance, and continuous improvement of its management systems(s).
DCF-763 · ISO/IEC 27001:2022: A.5.32
Cal.com's policies, procedures, and agreements include requirements for protection of intellectual of property rights and use of proprietary software products.
DCF-789 · ISO/IEC 27001:2022: 4.2
Cal.com has identified and documented the interested parties, their requirements and expectations of the organization (e.g., security and privacy expectations of customers, compliance expectations of regulators, business expectations of partners, performance and risks expectations of directors and investors, etc.), and how these requirements and expectations will be addressed.
DCF-41 · SOC 2: CC1.2
The board of directors includes members independent from management who are not involved in control operations.
DCF-63 · SOC 2: CC2.3
Cal.com maintains a publicly available terms of service for use of the system. All users must agree to the terms of service prior to using the system.
DCF-64 · SOC 2: CC2.3, CC3.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.316(a)
Cal.com communicates service commitments and system requirements to customers and other external parties, as appropriate, through contracts, agreements, company website, etc. Cal.com provides notification to relevant parties of any changes to service commitments and system requirements.
DCF-144 · SOC 2: CC1.2, CC1.3
The company's board of directors has a documented charter that outlines its oversight responsibilities for internal control.
DCF-146 · SOC 2: CC1.2, CC2.2, CC2.3, CC4.2
The company's board of directors, owners, senior leadership, or equivalent body, meets at least annually with management to review company performance, strategic objectives, compliance initiatives, and security and privacy risk and mitigation strategies. Meeting minutes, including decisions made and action items, are documented.
DCF-153 · HIPAA: 164.308(a)(8)
Cal.com performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings.
DCF-757 · SOC 2: CC2.2, CC2.3
Cal.com provides user guides, help articles, system documentation or other mechanisms to users to share information about the design and operation of the system and its boundaries. The information provided includes functional and nonfunctional requirements related to system processing and information specifications required to support the use of the system.
DCF-786 · SOC 2: CC2.2, CC3.1, CC3.2
Management has defined company objectives, including mission and vision statements, operational objectives at the entity and functional levels, financial performance goals, and other objectives as appropriate, to serve as the basis for risk assessment activities (e.g., objectives related to security, compliance, risk mitigation, etc.). Management communicates its objectives and any changes to those objectives to personnel.
DCF-65 · ISO/IEC 27001:2022: A.5.34 · SOC 2: CC2.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.316(a)
Cal.com maintains a publicly available privacy policy/notice.
DCF-527 · ISO/IEC 27001:2022: A.5.34 · SOC 2: CC1.3
Cal.com has appointed and documented responsibilities of an individual (e.g., data protection officer) responsible for developing, implementing, maintaining and monitoring an organization-wide governance and privacy program and acting as a point of contact to authorities and data subjects to ensure compliance with all applicable laws and regulations regarding the processing of PII.
DCF-113 · HIPAA: 164.306(e), 164.316(b)(1)(i), 164.316(b)(1)(ii)
Cal.com's management reviews the privacy notice to ensure that the privacy notice is accurate.
DCF-114 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.316(a)
Cal.com communicates its Privacy Policy on its public-facing website.
DCF-128 · HIPAA: 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C), 164.528(a), 164.528(b), 164.528(c), 164.528(d)
Cal.com discloses personal information only to third parties who have agreements with Cal.com to protect personal information in a manner consistent with the relevant aspects of Cal.com's privacy notice or other specific instructions or requirements.
DCF-129 · HIPAA: 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C), 164.528(a), 164.528(b), 164.528(c), 164.528(d)
Cal.com maintains a documented list of third parties and vendors that are authorized to receive or access PII
DCF-140 · SOC 2: CC2.3 · HIPAA: 164.530(d)(1), 164.530(d)(2)
Cal.com provides a contact mechanism for data subjects to submit privacy-related requests or report privacy incidents (e.g., email address, customer portal, etc.).
DCF-142 · HIPAA: 164.306(e), 164.316(b)(1)(i), 164.316(b)(1)(ii)
Executive management meets on a quarterly basis to review compliance with privacy practices and privacy regulations.
DCF-192 · HIPAA: 164.502, 164.504(e), 164.504(f), 164.504(g), 164.506, 164.508, 164.510, 164.512, 164.514, 164.520, 164.522, 164.524, 164.526, 164.528, 164.530, 164.532 (full HIPAA Privacy Rule scope)
Cal.com has a defined policy that establishes the requirements of the HIPAA Privacy Rule
DCF-195 · HIPAA: 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C), 164.314(a)(2)(ii), 164.314(a)(2)(iii)
Cal.com has a defined policy that establishes the requirements related to Business Associate Agreements
DCF-536 · SOC 2: CC2.2
Cal.com has established and documented records of processing activity (ROPA), which includes descriptions of the of lawful collection and use of PII as well as the specific purposes for which PII is processed.
DCF-537 · SOC 2: CC9.2
Cal.com has data processing agreements (DPAs) in place with sub-processors that include the minimum technical and organizational measures that the third parties need to implement to meet the objectives of Cal.com's privacy program.
DCF-15 · ISO/IEC 27001:2022: 6.1.1, 6.1.2, 6.1.3, 8.2, 8.3 · SOC 2: CC3.1, CC3.2, CC3.3, CC3.4, CC4.2, CC5.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B), 164.316(a)
Cal.com has defined and documented a process for risk assessment and risk management that outlines the organization's approach for identifying risks and assigning risk owners, the risk acceptance criteria, and the approach for evaluating and treating risks based on the defined criteria.
DCF-16 · ISO/IEC 27001:2022: 6.1.1, 6.1.2, 6.1.3, 8.2, 8.3 · SOC 2: CC3.1, CC3.2, CC3.3, CC3.4, CC4.2, CC5.1, CC5.2 · HIPAA: 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B), 164.308(a)(8)
Cal.com conducts risks assessments periodically as required by company policy and compliance requirements. The risk assessment includes consideration of threats and vulnerabilities and an evaluation of the likelihood and impact for each risk. A risk owner is assigned to each risk, and every risk is assigned a risk treatment option. Results of the risk assessment are documented (e.g., in a risk register).
DCF-17 · ISO/IEC 27001:2022: 6.1.2, 6.1.3, 8.1, 8.3 · SOC 2: CC3.1, CC3.2, CC3.3, CC3.4, CC4.2, CC5.1, CC5.2 · HIPAA: 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B)
Cal.com's management has documented a risk treatment plan to formally manage risks identified in risk assessment activities.
DCF-157 · SOC 2: CC9.1
Cal.com maintains cybersecurity insurance to mitigate the financial impact of security incidents and business disruptions.
DCF-778 · SOC 2: CC3.3
Cal.com performs an evaluation of fraud risks at least annually, either as a separate evaluation or as part of the overall enterprise risk assessment. The evaluation of fraud risk is performed in accordance with the company's risk assessment methodology.
DCF-31 · ISO/IEC 27001:2022: A.8.25, A.8.28 · SOC 2: CC8.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a), 164.530(c)
Cal.com has developed policies and procedures governing the system development life cycle, including requirements, design, implementation, testing, and deployment.
DCF-104 · ISO/IEC 27001:2022: A.8.27, A.8.33 · SOC 2: CC8.1
Test data is used in testing and development environments to prevent sensitive information from being copied to non-production environments.
DCF-312 · ISO/IEC 27001:2022: A.8.28 · SOC 2: CC1.4, CC2.2
Developers are required to complete secure code development training at least once every 12 months, including training on software security relevant to their job function and development languages, secure software design and secure coding techniques, and how to use tools for detecting vulnerabilities in software if these are used in the organization.
DCF-712 · ISO/IEC 27001:2022: A.8.8, A.8.28, A.8.29 · SOC 2: CC7.1, CC8.1
Cal.com uses static application security testing (SAST) or equivalent tool as part of the CI/CD pipeline to detect vulnerabilities in the codebase. When vulnerabilities are identified, corrections are implemented prior to release as appropriate based on the nature of the vulnerability.
DCF-784 · ISO/IEC 27001:2022: A.8.8, A.8.9, A.8.19, A.8.28 · SOC 2: CC7.1
Cal.com checks software components and libraries for policy and license compliance, security risks, and supported versions (e.g. using software composition analysis (SCA) tools in development pipeline, etc.). If vulnerabilities in these software components or libraries are identified, fixes are implemented in accordance with the company's vulnerability management policies.
DCF-503 · ISO/IEC 27001:2022: 7.3, 7.4, A.6.3 · SOC 2: CC2.2
Cal.com's security awareness program includes multiple methods of communicating awareness and educating personnel, such as newsletters, web-based training, in-person training, team meetings, phishing simulations, etc. Periodic security updates are provided to personnel through these multiple methods of communication.
DCF-681 · ISO/IEC 27001:2022: A.6.3 · SOC 2: CC1.4, CC2.2
Cal.com conducts periodic phishing simulations or social engineering tests as part of the company's security awareness initiatives.
DCF-196 · HIPAA: 164.308(a)(5)(i), 164.530(b)
Cal.com has established a training program for the use and disclosure of protected health information (PHI) to help personnel understand their obligations and responsibilities related to HIPAA. All eligible members of the workforce are required to complete this training during onboarding and annually thereafter.
DCF-746 · SOC 2: CC1.4, CC2.2
Cal.com has established training programs to help personnel understand their obligations and responsibilities for the protection of personally identifiable information (PII) and associated regulatory requirements. Personnel (including employees and contractors as applicable) are required to complete the training during onboarding and annually thereafter.
DCF-56 · ISO/IEC 27001:2022: A.5.19, A.5.20, A.5.21, A.5.22 · SOC 2: CC3.2, CC9.2 · HIPAA: 164.314(a)
Cal.com maintains a vendor/third party register that includes a complete and accurate list of vendors/third parties, relationship owners, description for each of the services provided, risk ratings, and results of vendor/third party risk management activities. Cal.com executes agreements with vendors and service providers involved in accessing, processing, storing or managing information assets that outline the responsibilities of each party.
DCF-57 · ISO/IEC 27001:2022: A.5.19, A.5.21, A.5.22 · SOC 2: CC3.2, CC9.2 · HIPAA: 164.308(b)(1), 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C)
Cal.com obtains and reviews compliance reports or other evidence for critical vendors and service providers at least annually to monitor the third parties' compliance with industry frameworks, regulations, standards (e.g., SOC 2, ISO, PCI DSS, etc.) and Cal.com's requirements. Results of the review and action items, if any, are documented.
DCF-132 · ISO/IEC 27001:2022: A.5.14, A.5.20, A.6.6 · SOC 2: CC2.3, CC9.2 · HIPAA: 164.308(b)(1), 164.308(b)(3), 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C)
Cal.com shares information with vendors and third parties only when an executed agreement (e.g., service agreements, business associate agreements, data processing agreements, etc.) is in place that includes security, confidentiality, and privacy requirements for the transfer and processing of information.
DCF-168 · ISO/IEC 27001:2022: A.5.19, A.5.21, A.5.23 · SOC 2: CC9.2 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.308(b)(1), 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C), 164.314(a)(2)(ii), 164.314(a)(2)(iii), 164.314(b)(1), 164.314(b)(2)(i), 164.314(b)(2)(ii), 164.314(b)(2)(iii), 164.314(b)(2)(iv), 164.316(a), 164.504(e), 164.504(f)
Cal.com has a documented policy that outlines requirements for managing vendor and third-party relationships through their entire life cycle.
DCF-507 · ISO/IEC 27001:2022: A.5.19, A.5.20, A.5.21, A.5.23 · SOC 2: CC3.2, CC9.2
Cal.com performs due diligence activities prior to engaging with a new service provider or vendor (e.g., review of security questionnaires and compliance reports, review of vendor-provided policies, procedures, or other documents, analysis of delegated or shared responsibilities with the prospective vendor, etc.). Results of the due diligence activities including action items are documented.
DCF-762 · ISO/IEC 27001:2022: A.5.22
Changes to the provision of services by vendors, including expansions of services and supplier changes, require review and due diligence activities and are authorized by management. Documentation of the due diligence activities and authorization is retained.
DCF-40 · HIPAA: 164.308(b)(1)
Cal.com requires its contractors to read and acknowledge the Code of Conduct, read and acknowledge the Acceptable Use Policy, and pass a background check.
DCF-66 · SOC 2: CC2.3
Master service agreements outlining specific requirements are executed with enterprise customers or when the standard terms of service may not apply.
DCF-133 · HIPAA: 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C)
Cal.com requires vendors and third parties with access to personal information to sign a formal contract that requires them to notify Cal.com in the event of actual or suspected unauthorized disclosures of personal information
DCF-134 · HIPAA: 164.314(a)(1), 164.314(a)(2)(i)(A), 164.314(a)(2)(i)(B), 164.314(a)(2)(i)(C), 164.402
Cal.com provides vendors and third parties with information on how to report breaches to Cal.com.
DCF-136 · SOC 2: CC2.3 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.316(a)
Cal.com communicates to customers any use of subprocessors to process PII (e.g., through a list of subprocessors in the company website or data processing agreement, etc.). Cal.com obtains authorization from customers for the use of subprocessors (e.g., through executed data processing agreements, accepting the terms in the website, etc.).
DCF-543 · SOC 2: CC2.3
Cal.com notifies customers of any intended changes (including additions and replacements) in subprocessors that process PII so that customers have an opportunity to object to such changes.
DCF-18 · ISO/IEC 27001:2022: A.8.8 · SOC 2: CC3.2, CC4.1, CC5.2, CC7.1 · HIPAA: 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B)
Cal.com conducts vulnerability scans of the production environment as dictated by company policy and compliance requirements. Results are reviewed by company personnel and vulnerabilities are tracked to resolution in accordance with company policies.
DCF-152 · ISO/IEC 27001:2022: A.8.8, A.8.19 · SOC 2: CC6.8, CC8.1
Cal.com has implemented automated mechanisms (e.g., unattended upgrades, automated patching tools, etc.) to install security fixes to systems.
DCF-183 · ISO/IEC 27001:2022: A.8.8 · SOC 2: CC5.3, CC7.1 · HIPAA: 164.306(a), 164.306(b), 164.306(c), 164.306(d), 164.306(e), 164.308(a)(1)(i), 164.316(a)
Cal.com has a defined policy that establishes requirements for vulnerability management across the organization, including monitoring, cataloging, and assigning risk ratings to vulnerabilities to prioritize remediation efforts.
DCF-785 · ISO/IEC 27001:2022: A.8.9 · SOC 2: CC7.1
Cal.com maintains secure and supported configuration standards and versions for system components and replaces those components when support is no longer available from the developer, vendor, or manufacturer. Where unsupported components cannot be replaced, Cal.com identifies and documents risk mitigation strategies.
DCF-191 · HIPAA: 164.308(a)(5)(ii)(A)
Cal.com has documented procedures for periodic communication of security updates and reminders to all personnel, and other interested parties when appropriate
DCF-677 · SOC 2: CC8.1
Cal.com has implemented a software update management process where critical patches and application updates are installed for all authorized software within priority SLAs established in company policies.
Subprocessors
19 third parties process customer data on our behalf. The full list, with what each one does and where, is public.