Security built into the platform
TLS encryption in transit; data at rest encrypted by our cloud providers (Neon, Vercel). Role-based access controls. We do not claim SOC 2 certification or uptime SLAs on the marketing site until verified.
30-day free trial on paid plans · Free plan at $0
Platform security
Infrastructure & data
Controls we operate today for multi-tenant scheduling — not marketing theater.
Encryption in transit & at rest
Modern cloud infrastructure
Tenant isolation
Operational monitoring
Identity & access
Who can do what
Account security for owners, staff, and platform operators.
Authentication
Multi-factor authentication
Role-based access
Abuse prevention
Privacy & compliance
What we claim — and what we don't
We do not market SOC 2, ISO, or HIPAA compliance on this page unless and until those programs are complete and legally approved.
Payments
Card data is handled by Stripe Checkout — Cicini does not store full card numbers or CVV in the application database.
Privacy & residency
Cicini is a Canadian company (Toronto). Application data is hosted on major cloud providers (e.g. Neon/Vercel regions chosen for reliability). We do not currently guarantee exclusive Canadian data residency or a Canada-only region pin. Contact us via /demo if residency is a procurement requirement.
Compliance honesty
Cicini uses technical safeguards including encryption and role-based access controls. A signed Business Associate Agreement and dedicated compliance tier are planned for Enterprise. They are not currently available on Free, Starter or Professional plans.
Penetration testing
Independent testing summary
A sanitized summary. We do not publish exploit details or vulnerability chains.
Status
An independent third-party penetration test has not yet been completed. We will update this page with a sanitized summary once a report is received.
What we will publish
Test date, scope, overall outcome, and remediation status by severity. No exploit steps, payloads, or vulnerability chains.
Remediation commitment
Critical findings are targeted for a fix within 7 days and High within 30 days, followed by an independent retest within 90 days of the report.
Questions about security?
Start free to explore the product, or contact us for enterprise security discussions — including BAA needs for regulated workflows.
30-day free trial on paid plans · Free plan at $0
