Security

How we protect your data, and how we check

What we do to keep merchant and customer data safe, how we test it, and what we have not done yet.

The short version

  • Opencals has not been audited or certified by an independent third party. We do not hold a SOC 2 report or an ISO 27001 certificate, and there is no official HIPAA certification.
  • We assess ourselves against the technical controls in SOC 2, ISO 27001, the HIPAA Security Rule and GDPR. We use Prowler for our AWS account and GitHub organisation, and Aikido for our code, dependencies and cloud setup. We fix what they find and re-scan.
  • Production runs on AWS in London. Card payments go through Stripe, and we never see card numbers.
  • Every merchant gets a Data Processing Agreement, and US healthcare customers can sign a Business Associate Agreement. Ask us and we will send a summary of our latest scan results under NDA.

Last full assessment: 2 October 2026

Frameworks

What each badge on our site means

For each one: what it is, what we check, and what our checks do not cover.

Where data is hosted

AWS London, UK

Production runs on Amazon Web Services in the London region (eu-west-2). Databases, file storage, backups, email sending and most AI processing stay in that region. The UK has an EU adequacy decision, so moving data between the EU and the UK needs no extra safeguards.

What we check

  • Prowler scans run against the London region, and checks in every other region are muted only for services we don't use there.
  • Global services (CloudFront, IAM, WAF) are scanned too.

What this does not cover

  • Website pages are delivered through AWS's global CDN, so cached public pages are served from edge locations worldwide.
  • Some third-party services process data outside the UK and EEA. They are listed in the subprocessors section below.
  • Some requests from our onboarding assistant may be routed to AWS regions outside Europe (Amazon Bedrock cross-region inference).

GDPR and UK GDPR

DPA available

The EU's data protection law and its UK equivalent. When a clinic or business uses Opencals, it is the controller of its customers' data and we are its processor.

What we check

  • Prowler's GDPR checks on our AWS setup: encryption, logging and access monitoring.
  • A Data Processing Agreement (art. 28) that every merchant gets, a published list of subprocessors, and a privacy policy that matches how we actually run.
  • Data subject requests (access, export, deletion) handled by the founder within one month.

What this does not cover

  • No external audit of our GDPR processes.
  • Merchants remain responsible for their own lawful basis, consent forms and notices to their customers.

SOC 2

Controls self-assessed

A framework from the AICPA for how service providers protect customer data. A SOC 2 report is issued by an independent CPA firm after an audit. We do not have a SOC 2 report.

What we check

  • Prowler's SOC 2 mapping on our AWS account: access control, logging, monitoring, change tracking, encryption and backups.
  • Prowler's GitHub checks on our repositories: branch protection, required reviews, secret exposure and access settings.
  • Aikido scanning of our code, dependencies and cloud setup for known vulnerabilities and leaked secrets.

What this does not cover

  • No independent auditor has tested our controls, so we cannot provide a SOC 2 Type I or Type II report.
  • Automated checks cover technical configuration. They do not test written policies, vendor management or HR processes the way an auditor would.

ISO/IEC 27001

Controls self-assessed

An international standard for running an information security management system. Certification is granted by an accredited body after an audit. Opencals is not ISO 27001 certified.

What we check

  • Prowler's ISO 27001:2022 mapping of the Annex A technical controls on our AWS account.
  • The same GitHub and Aikido scanning described under SOC 2.

What this does not cover

  • No certification and no external audit.
  • Many ISO 27001 requirements are organisational (risk management, policies, training, supplier reviews). Automated scans cannot check these. We are writing that policy set now.

HIPAA

BAA available

The US law on protected health information (PHI). There is no official HIPAA certification. A US healthcare provider can only put PHI in a vendor's system after signing a Business Associate Agreement (BAA) with that vendor.

What we check

  • Prowler's HIPAA Security Rule mapping of the technical safeguards on our AWS account: access control, audit logging, integrity and transmission security.
  • We sign a Business Associate Agreement with US healthcare customers on request. PHI should only go into Opencals after the BAA is signed.
  • Our hosting and email run on AWS services covered by AWS's own BAA with us.

What this does not cover

  • No third-party HIPAA assessment. Automated scans check technical safeguards, not administrative or physical ones.
  • Optional integrations a merchant turns on (for example Zapier or Google Calendar) are outside our BAA. Don't send PHI through them unless you have your own BAA with that provider.

Controls

What we actually do

Running in production

In place on the live platform today.

  • InfrastructureProduction hosted on AWS in London (eu-west-2)
  • InfrastructureAll web and API traffic served over HTTPS (TLS)
  • InfrastructureDisk encryption on by default for new compute volumes; instance metadata v2 required
  • AccessNo day-to-day admin access: production AWS changes go through a role that requires multi-factor authentication, with sessions limited to 12 hours
  • AccessAWS root account protected by a hardware MFA key and kept for emergencies only
  • AccessIAM Access Analyzer flags any resource shared outside our account
  • MonitoringCloudTrail records API activity in every region, with log file integrity validation and encryption under our own KMS key
  • MonitoringAmazon GuardDuty threat detection, including AI workload protection
  • MonitoringAWS Security Hub (Foundational Best Practices and CIS benchmarks) and AWS Config recording every resource type
  • MonitoringApplication errors tracked in Sentry (EU data region)
  • ApplicationCode, dependencies and cloud setup continuously scanned by Aikido; findings triaged by severity
  • ApplicationRole-based access control for merchant staff in the dashboard
  • DataCard payments handled by Stripe (PCI DSS Level 1). Opencals never sees or stores full card numbers
  • InfrastructureWeb application firewall with managed rule sets and per-IP rate limiting on every site
  • InfrastructureDatabase connections required to use TLS
  • InfrastructureUploaded media served only through the CDN, with direct public bucket access switched off
  • AccessApplication servers use short-lived role credentials instead of stored access keys; secrets kept in AWS Secrets Manager
  • DataAutomated backups of the production database: daily (kept 35 days) and monthly (kept 12 months), in an encrypted backup vault
  • DataDatabase standby in a second availability zone
  • ApplicationPublic Storefront API responses trimmed to what a booking page needs, with staff contact details removed
  • MonitoringApplication, firewall and CDN logs encrypted with our own KMS key and kept for 90–180 days

Planned

Not done yet. Listed so you know where we are going.

  • AssuranceIndependent penetration test
  • AssuranceWritten security policy set (access, incident response, vendor review, risk register)
  • AssuranceSOC 2 Type I audit by an independent firm
  • DataOnboarding-assistant AI requests kept inside European AWS regions

Subprocessors

Who else handles data

Integrations a merchant connects (Google Calendar, Zapier, Shopify) only receive data if the merchant turns them on.

ProviderPurposeLocation
Amazon Web ServicesHosting, database, storage, backups, email (SES), AI models (Bedrock)UK (London); global CDN for web delivery
StripePayments and subscriptionsEU, US
ShopifyOnly for merchants using the Shopify appCanada, US and others
GoogleCalendar and Meet sync (optional), address lookup, website analyticsUS and others
Microsoft ClarityWebsite session analytics, with consentUS
SentryError monitoringEU (Germany)
SlackInternal alerts and onboarding-assistant escalationsUS
ZapierOnly if a merchant connects itUS

Found a vulnerability?

Email security@opencals.com with steps to reproduce. We reply within two business days. Please give us a reasonable time to fix it before you disclose it publicly, and don't access other people's data while testing.

Need this for procurement?

We can send a written summary of our latest scan results under NDA, sign our DPA or a HIPAA Business Associate Agreement, and fill in your security questionnaire. Write to security@opencals.com.

About this page

This page describes our security practices and how we assess them. It is not a certification, an audit report or a guarantee. References to SOC 2, ISO/IEC 27001, HIPAA and GDPR describe the frameworks we test against, not certifications or attestations. Opencals is not affiliated with or endorsed by the AICPA, ISO, or the U.S. Department of Health and Human Services. Automated tools check technical configuration and cannot verify every requirement of a framework.

Our contractual commitments are in our Terms, Privacy Policy and Data Processing Agreement. We update this page as things change. Opencals is run from Warsaw, Poland.

Get started

Ready to transform your service business?

Join 150+ businesses already using Opencals. Start on a free development store with every feature unlocked, and only pay once you go live.

No credit card required
Setup in 10 minutes
Cancel anytime