Security
How we protect your data
Cals connects to your calendar, so we keep what we store small and protect it carefully. Here is what we do today.
Encrypted in transit
Every connection to Cals uses TLS (HTTPS).
Encrypted calendar tokens
The tokens that let Cals read your free and busy times are encrypted at rest with AES-256-GCM.
Password hashing
Passwords are hashed with scrypt. We never store or see your password.
Signed webhooks
Webhooks we send are signed so your systems can check they came from Cals.
Hosted on Cloudflare
Cals runs on Cloudflare's network.
Export and deletion
Workspace owners can export their records and delete the workspace from settings.
Report a security issue
If you think you have found a vulnerability, email us with the details and steps to reproduce. We will reply and keep you updated while we fix it.