Security & Trust
CalibraCore is built to keep your calibration records safe, private and available. This page explains how we protect your data. We describe our actual practices honestly — where a formal certification is not yet in place, we say so rather than imply it.
Where your data is hosted
CalibraCore runs on managed cloud infrastructure. The application is served from a global edge network, and your data is stored in a PostgreSQL database. Each organization's data is logically isolated so one customer cannot see another customer's records.
Encryption in transit
All traffic between your browser and CalibraCore is encrypted using HTTPS / TLS. Data is never transmitted in plain text over the public internet.
Access control
Access is protected by authentication and role-based access control (RBAC). Owners and admins decide which team members can view or change instruments, calibrations and settings. Every user only sees data belonging to their own organization.
Backups & availability
Your database is backed up automatically on a regular schedule, so your calibration history is protected against accidental loss. The platform is cloud-hosted for high availability, with updates applied for you — no servers for you to patch or maintain.
Your data is yours
You own your data. You can export your instruments and calibration history to Excel or CSV at any time, and you can request deletion of your organization's data when you close your account.
Sub-processors
We use a small number of trusted infrastructure and service providers to run CalibraCore (for hosting, database, email and payment processing). We can share our current list of sub-processors on request as part of our Data Processing Agreement.
Compliance approach
CalibraCore is designed to help you keep the records that quality standards such as ISO 9001, ISO/IEC 17025, IATF 16949 and AS9100 require for measuring equipment — calibration schedules, history and traceable certificates. We continue to strengthen our security programme and are happy to complete customer security questionnaires. We do not claim certifications we have not yet obtained.
DPA and NDA
A Data Processing Agreement (DPA) and a Non-Disclosure Agreement (NDA) are available on request for customers who need them before purchasing — common for enterprise and EU/UK buyers.
Reporting a security concern
If you believe you have found a security issue, please email support@calibracore.com and we will respond promptly. Please do not share details publicly until we have had a chance to investigate.
Questions about security or compliance? Contact us and we will help.