Implemented
Current website controls
HTTPS redirection, HSTS, secure cookies, CSRF protection, clickjacking protection, host validation, and request rate limits are configured for production.
Security, privacy, and deployment
This page separates controls that the current website code proves from product controls that depend on the selected deployment. Caracal will not claim a certification or control until there is evidence for it.
Implemented
HTTPS redirection, HSTS, secure cookies, CSRF protection, clickjacking protection, host validation, and request rate limits are configured for production.
Deployment requirement
Product access, tenant isolation, at-rest encryption, backups, retention, residency, and integrations depend on the hosted, VPC, or on-premise design.
Planned
Independent testing and certification can start after production controls are stable and repeatable. No current certification is claimed.
Control register
The status shows what is true now. The evidence line shows what a buyer can request before client data enters the platform.
Implemented for the production website
Production settings redirect HTTP to HTTPS, enable HSTS, and mark session and CSRF cookies as secure. Hosted product deployments must use TLS for user and integration traffic.
Buyer evidence
Django production security settings and deployment configuration.
Deployment requirement
A production or pilot design must document encryption for databases, object storage, backups, and secrets. The public website repository does not prove a product-wide at-rest encryption control.
Buyer evidence
Confirm the selected hosting service, key-management method, and backup configuration before a pilot starts.
Deployment requirement
The marketing site uses Django administrative authentication. Product access roles, identity-provider integration, multi-factor authentication, and least-privilege rules must be agreed and tested for each deployment.
Buyer evidence
Provide a role matrix and authentication test results during security review.
Baseline defined; product evidence required
Production logging is configured for the website. Product deployments must record sign-in, access, configuration, integration, export, and administrative events without placing client content in logs by default.
Buyer evidence
Provide a sample audit event, access rules, retention period, and export method.
Defined per deployment
The pilot scope must state which client records are stored, how long they are kept, when backups expire, and how verified deletion is completed after the pilot or contract.
Buyer evidence
Add the agreed schedule to the data-processing and pilot documents.
Architecture-dependent
Isolation can use a dedicated environment, a client VPC, or an on-premise deployment. A shared hosted service must prove logical isolation before it is used for client data.
Buyer evidence
Provide an architecture diagram, authorization tests, and storage boundaries for the selected model.
Deployment requirement
The recovery design must state backup frequency, encryption, retention, restore tests, recovery point objective, and recovery time objective. No public certification claim is made.
Buyer evidence
Provide the latest restore-test record and the agreed recovery objectives.
Current website baseline
The application uses pinned project dependencies, production checks, secure framework settings, and rate limits. The operating process must add dependency review, patch targets, scanning, and remediation priority based on exploit evidence.
Buyer evidence
Track dependency updates and use the CISA Known Exploited Vulnerabilities Catalog as one priority input.
Plan milestone
A documented response plan must define detection, triage, containment, notification, recovery, evidence preservation, and post-incident review before production client data is accepted.
Buyer evidence
Provide the plan owner, contact route, notification terms, and exercise record.
Must be disclosed before processing
The current website can use hosting, email, booking, and optional analytics services. A product deployment must provide the exact subprocessor list and purpose before client data is processed.
Buyer evidence
Publish or attach the deployment-specific subprocessor schedule.
Deployment choice
Hosted region, cross-border transfers, backup location, and support access must be agreed before a pilot. Dedicated VPC and on-premise paths can be evaluated when the client requires them.
Buyer evidence
Record the chosen region and all transfer paths in the deployment design.
Pre-pilot policy requirement
Pilot and production terms must prohibit use of client data to train shared models by default. Any different use must have a separate written purpose, approval, data scope, retention rule, and deletion method.
Buyer evidence
Include this rule in the pilot and production data terms.
Clear terminology
The old phrase was ambiguous. It could mean that Caracal handles controlled technology. That is not the intended claim.
Controlled data flows means that each deployment defines approved sources, destinations, storage locations, access roles, exports, and retention rules. Caracal can monitor public export-control changes as operational risk evidence. Caracal does not decide legal classification or replace formal export-control review.
Caracal does not replace legal, customs, or compliance advice.
Certification milestones
Security references