CaptivaHQ
Industries

Find your industry

Property Management & HOAMaritime & Fleet OperationsIndustrial & ManufacturingLegal & LawFinancial ServicesHealthcare AdministrationInsuranceHospitality & RestaurantsGovernment & Public SectorSkilled TradesCustom CRM / ERPExplore all industries →
Modules AI Compare Pricing FAQ Docs Partners
Contact Us

← Legal hub

Legal · Effective September 26, 2026

Security overview

This overview describes the technical and organisational measures United Technology Services Inc. uses to protect CaptivaHQ and the data you put into it. It is Annex 2 of our Data Processing Agreement. For what you are responsible for, see the Shared Responsibility Model.

On this page

  1. Architecture and tenant isolation
  2. Encryption
  3. Identity and access
  4. Logging and audit
  5. AI safety
  6. Secure development
  7. Availability and backups
  8. Incident response
  9. People and suppliers
  10. Certifications and reports
  11. Reporting a vulnerability

1. Architecture and tenant isolation

  • Regional cells. Each customer is assigned to a regional cell, United States or European Union, and its records stay in that cell. A small platform directory of identities and sign-in records is held in France.
  • Schema per tenant. Every workspace has its own database schema, and row-level security enforces workspace boundaries inside shared services.
  • Least privilege between services. Services hold only the credentials they need. Secrets live in a managed secret store, never in source code.

2. Encryption

  • In transit. All traffic to the application uses TLS. HTTP Strict Transport Security is enforced for two years, including subdomains, with the preload directive set. Outbound email uses TLS 1.2 or higher.
  • At rest. Databases, file storage and backups are encrypted at rest by our infrastructure providers. OAuth tokens for connected accounts and message content from Google are additionally encrypted with AES-256.

3. Identity and access

  • Sign-in by one-time code or single sign-on with Google or Microsoft, with session rotation and request-forgery protection.
  • Role-based permissions inside each workspace, managed by the customer's administrators.
  • API and MCP access by revocable, scoped keys.
  • UTS staff access to production is limited to named engineers, protected by multi-factor authentication, logged, and used only to operate the Service, answer a support request you filed, investigate a security incident or meet a legal obligation.

4. Logging and audit

  • Sign-ins, authentication events and field-level changes to records are logged and kept for 3 years.
  • Every AI model call is logged with a redacted preview (at most 200 characters) and kept for 90 days; AI transaction records expire after 7 days.
  • Customers can review their workspace's history of changes in the product.

5. AI safety

  • Customer Data is not used to train foundation models, ours or our providers'.
  • AI agents act with the permissions of the user or role that configured them, and consequential actions can be set to require human approval.
  • Content from emails, documents and the web is treated as untrusted input to reduce prompt-injection risk.
  • AI Features can be switched off per workspace, and enrichment and web-grounded answers individually.

6. Secure development

  • Source code is kept on self-hosted, access-controlled infrastructure. Changes go through review and automated tests before deployment.
  • Dependencies are tracked and updated; security fixes are prioritised.
  • Production and development data are separated; customer data is not used for testing.

7. Availability and backups

  • Continuous monitoring and alerting on the application and its dependencies.
  • Regular database backups, kept encrypted and on a rolling retention cycle.
  • Availability commitments are in the Service Level Agreement.

8. Incident response

  • A documented incident-response procedure covers detection, containment, investigation, notification and review.
  • We notify affected customers of a personal-data breach without undue delay, and in any case within 72 hours of becoming aware of it, with the information they need to meet their own obligations.

9. People and suppliers

  • Staff and contractors with access to customer data are bound by confidentiality obligations and receive security training.
  • Access is removed promptly when someone changes role or leaves.
  • Sub-processors are assessed before use and bound by written data-protection terms. The current list is on the sub-processors page.

10. Certifications and reports

Our infrastructure providers maintain their own certifications, such as ISO/IEC 27001 and SOC 2, which cover the physical and hosting controls we inherit. CaptivaHQ itself has not yet completed an independent SOC 2 or ISO/IEC 27001 audit; we will publish the reports here when it has. Until then, we answer reasonable security questionnaires on request at [email protected].

11. Reporting a vulnerability

Email [email protected] with a description and steps to reproduce. Please give us reasonable time to fix the issue before disclosing it, and do not access other customers' data or degrade the Service while testing. We will not pursue good-faith research that follows these rules.

Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].

CaptivaHQ

The AI-first Enterprise Operating System. Built by United Technology Services.

Modules AI Compare Pricing FAQ Docs Partners utsconsult.com Privacy Policy Terms of Service Legal
© 2026 United Technology Services Inc. CaptivaHQ is a product of UTS. All rights reserved. Enterprise operating system · AI-first ERP alternative · modular business platform