The Celigo platform is built using industry-standard technology frameworks and secure software development practices. Production and testing environments are completely segregated, and customer data is never used in QA or developer testing.
Celigo has a designated Sr. Director of Security and Compliance and Data Protection Officer to lead the Security and Compliance Team and work with technical staff to support the implementation of the security requirements needed to operate at the levels of security and compliance that Celigo and its customers expect.
This article is the central reference for Celigo's security and compliance capabilities, including protocols, access controls, certifications, and data protection.
For more information:
- Celigo security overview
- Celigo Trust Center
- Transport Layer Security (TLS)
- Platform security guidelines
- Keep your data secure while integrating with Celigo
Protocols
- Incoming connections: Transport Layer Security (TLS) 1.2
- HTTPS client traffic: TLS 1.2
- Endpoint or FTP connections: TLS 1.2 and TLS 1.3. See Supported Transport Layer Security(TLS) versions.
Application authorizations and trusted connections
Account owners and administrators fully control authorization at the user and application levels. They can also grant Celigo Support representatives secure, controlled, and time-bound access to their environments.
Audit logs
Keep track of activity on your account for up to a year. Monitor integration and flow changes over the course of the resource's lifecycle.
Security controls
The following index summarizes Celigo's security controls, with links to detailed documentation for each capability. Availability for some capabilities varies by edition. See Celigo platform editions.
- Identity and authentication: Celigo supports username and password login, Google account linking, OpenID Connect (OIDC) single sign-on, and multi-factor authentication (MFA) using time-based one-time passwords (TOTPs). SSO is available as an add-on on Standard and is included on Professional and Enterprise editions. See Account administration.
- Role-based access: Account owners and administrators assign one of four permission tiers per integration: Monitor, Manager, Administrator, and Owner. Celigo Support access can be granted as secure, controlled, and time-bound. Available on all editions. See Account administration.
- Encryption in transit: The Celigo platform supports TLS 1.2 and TLS 1.3 for all connections. TLS 1.0 and TLS 1.1 are no longer supported as of September 30, 2025. Available on all editions. See Supported Transport Layer Security (TLS) versions.
- Encryption at rest: Data temporarily stored in AWS is encrypted using AES-256. All Amazon S3 buckets use SSE-S3 encryption, with each file's key stored separately under a master key. Available on all editions. See Platform security guidelines.
- Credential protection: Credentials stored in integrator.io, including endpoint API credentials (API tokens, OAuth secrets, SFTP passwords) and integrator.io user account passwords, are encrypted using AES-256. The AES-256 encryption key is derived using PBKDF2, and these encryption keys are stored in access-restricted Amazon S3 buckets, accessible only from within Celigo's VPC. Customers are responsible for rotating endpoint API tokens and passwords according to their own security policies. Available on all editions. See Platform security guidelines.
- Audit logging: Celigo logs user activity, including sign-in and sign-out events and IP addresses. Audit log retention varies by edition: 1 year (Standard), 2 years (Professional), 3 years (Enterprise). See Account administration.
- Execution and error logging: Celigo retains run history, flow run details, error records, and debug logs. Default retention is 30 days; extended retention is available depending on your subscription. See Retain your log and error data for more than 30 days.
- Data retention: Error data is retained for 30 or more days depending on your Celigo license: 30 days (Standard), 60 days (Professional), 180 days (Enterprise). You can delete records or exercise your Right to Delete in support of GDPR and CCPA compliance. See: Retain your log and error data for more than 30 days.
- Data residency: Celigo Private Cloud supports regional deployment across the United States, Canada, Europe, Asia-Pacific, Africa, the Middle East, South America, and Israel, keeping data within required geographic boundaries for GDPR, CCPA, and similar regulations. Available on Celigo Private Cloud. For the full list of locations, see Data residency and compliance for Celigo Private Cloud.
- Private Cloud: Celigo Private Cloud provides dedicated, isolated instances with regional hosting, custom compliance configurations for HIPAA and PCI DSS, proactive monitoring, and incident response. Available as a separate subscription. See Data residency and compliance for Celigo Private Cloud.
- AI governance and guardrails: Celigo's platform supports TRiSM (Trust, Risk, and Security Management) principles by enabling output validation, human-in-the-loop safeguards, and full audit trails for AI-driven workflows. Available on all editions. See Enhancing AI enablement with TRiSM: Trust, risk, and security in action.
- Compliance certifications and assurance: Celigo holds SOC 2 Type II certification and is ready for HIPAA, HiTech (as a qualified Business Associate), FERPA, GDPR, and US/EU/UK/Swiss Data Privacy Frameworks. The platform supports FedRAMP-certified organizations without holding FedRAMP certification itself. See the Regulatory compliance and Voluntary compliance sections in this article.
Regulatory compliance
Celigo handles all data at the highest level required for regulatory and voluntary compliance requirements, ensuring cloud security at multiple levels:
EU and UK
- EU/UK GDPR-Ready
Contact Celigo for a Data Processing Agreement (DPA).
US State Privacy (A US Data Privacy addendum is available)
- California CCPA/CRPA - Ready
- Nevada Chapter 603-A – Covered by GDPR and CCPA - Ready
- New York SHIELD ACT – Covered by GDPR and CCPA - Ready
- Virginia Consumer Data Protection Act (VCDPA) - Ready
- Texas Data Privacy and Security Act (TDPSA) - Ready
Voluntary compliance
- SOC 2 Type II compliant
- As a customer or a prospect, you may request a copy of the SOC 2 report under Mutual NDA from compliance@celigo.com.
- HIPAA – HIPAA-ready, though not HIPAA-certified
- HiTech – Not HiTech standard-certified, though qualified to support HiTech standard-certified companies (as a Business Associate to either a Covered Entity or another Business Associate) under the certified HiTech service providers' infrastructure
- Status – The Celigo Security Team has completed implementation for infrastructure encryption: restricted access to ePHI data, trained select staff, and provided secure laptops with full-disk encryption
- FERPA-ready
- FedRAMP – Not certified, since Celigo is not directly U.S. government-facing, but we can support companies that are FedRAMP certified as part of the certified FedRAMP service providers' infrastructure
- US, EU, UK, and Swiss Data Privacy Framework Certified
Data retention
The error data retention period lasts for 30 or more days, based on your Celigo license. You can delete records if you choose to or if your customers exercise their Right to Delete.
Data protection
Data is encrypted in motion and at rest, according to country-specific data protection and privacy guidelines:
- All data in motion inside AWS VPC: Encrypted at TLS 1.2 or better
- All data temporarily stored in AWS: Encrypted with AES-256
- Stored credentials: Encrypted with AES-256, using a key derived via PBKDF2
The Celigo platform supports the highest level of HTTPS API TLS encryption available. For example, when NetSuite supports TLS 1.2, the Celigo connection is also encrypted to TLS 1.2. Therefore, it is the customer's responsibility to ensure that the endpoint encryption is at least TLS 1.2. Otherwise, that particular segment of the data flow may not be considered securely encrypted, or encrypted at all in the case of an HTTP API.(TLS 1.0 and TLS 1.1 are no longer supported by the Celigo platform as of September 30, 2025. See Supported Transport Layer Security (TLS) versions.)
Encryption keys
Celigo has enabled SSE-S3 for all Amazon S3 buckets. Each file saved in S3 is encrypted, and its Key is encrypted using a master key stored separately.
API credential security
You provide your API credentials for your endpoint, then they are encrypted and stored in integrator.io for subsequent flow steps.
Professional Services customer credentials vaulting
Need help developing flows? You can provide your credentials to us securely so that we can build it for you.
Security and compliance resources
The following articles provide detailed documentation for specific security and compliance topics:
- Platform security guidelines
- Supported Transport Layer Security (TLS) versions
- Retain your log and error data for more than 30 days
- Data residency and compliance for Celigo Private Cloud
- Account administration
- Enhancing AI enablement with TRiSM: Trust, risk, and security in action
- Celigo Trust Center