Castan

Security

Reviewed September 6, 2026

Castan reads a company's most sensitive material: its inbox, its chats, its calls, its books. This page says how that material is protected, in plain words, and lists only what is in place today. Where a control depends on configuration, this page reads the live configuration, so nothing here is aspirational.

Where your data lives

The application runs on Railway in the European Union (Amsterdam). The database is Neon Postgres in the European Union (Frankfurt), encrypted at rest, with point-in-time recovery for the last seven days. Meeting audio is captured by Recall.ai in the region configured for the account and transcribed there; the transcript is stored with your workspace in the EU. Text sent to the language model is processed by Anthropic in the United States under commercial terms that forbid training on it. Card details go to Stripe and never touch our servers.

One workspace cannot see another

Every table that holds customer data carries the workspace it belongs to, and Postgres row-level security is switched on and enforced for the role the application connects with. A query without a workspace context returns nothing, not everything. The few lookups that must cross workspaces (an invite link, an API key, a public recap link) go through single-purpose database functions that return one row by an unguessable token. This is isolation by the database, not by application code remembering to add a filter.

Read-only by construction

Sources are connected with the narrowest scopes that exist: Gmail read-only, Calendar read-only, Slack read scopes for the channels the bot is invited to (never direct messages; the bot cannot post), a Stripe restricted key with read permissions only. Castan cannot send mail from your mailbox, move money or write to your books. The only mail it sends is its own: meeting recaps, invitations, its notices to you, and an invoice reminder once you approve a chase, with you in copy. The one deliberate exception is the Studio, which opens pull requests on repositories you choose with a GitHub token you provide; every change still arrives as a pull request for a human to merge.

Who in your company sees what

Owners see everything the workspace knows. Members ask the same brain but financial sources (Stripe, books) are excluded from their answers, in the product and over the API alike. API keys are stored as hashes, shown once, and can be revoked at any time; each key carries its role.

Encryption

Everything travels over TLS. Storage is encrypted at rest by the providers above. OAuth tokens for connected sources are additionally encrypted at the application layer (AES-256-GCM) with a key that lives only in the server environment, so a copy of the database alone yields no usable credentials.

AI, kept on a leash

Text that comes from outside (an email body, a chat message, a transcript, a file in a repository) is wrapped in explicit untrusted-content markers before it reaches the model, with standing instructions to treat anything inside them as data, never as commands. Agents propose; you approve. What each agent may do without asking is set per workspace and defaults to asking. Your data is never used to train models, ours or anyone else's.

Every action leaves a trace

An append-only audit log per workspace records agent runs, approvals, connection changes, billing events and setting changes, with who or what caused them.

The meeting assistant

It joins calls visibly, under the Castan name, only for meetings your workspace sends it to. Recap pages are unlisted, excluded from search engines and can be protected with a passcode.

Pages published through Castan

An idea page Castan hosts for a customer is written by our agent from the customer's brief, sanitized to a fixed allow list (no scripts but our own sign-up handler, no forms but the waitlist, no frames, no external assets), served with a content security policy that enforces the same, and published on a separate domain so it never shares castan.ai's origin or reputation. Each page names its publisher and carries a report link; founded reports lead to a takedown.

Deleting your data

Removing a source stops new ingestion and deletes, at once, everything that came through that connection: its threads, messages, meetings, tasks and documents and their search index. People and companies, which other sources also know, stay; the invoices and payments imported from a Stripe connection are your books and stay. The removal screen shows the exact counts before you confirm. Deleting a workspace removes everything within 30 days, backups included, which is why our backup retention never exceeds 30 days.

What we do not have yet

No SOC 2 report and no ISO 27001 certificate. Both are planned for when a customer's procurement asks for them; until then this page, our privacy policy with its subprocessor list, and a data processing agreement on request are what we can offer. A Google security assessment (CASA) is part of releasing the Gmail connection to the public and will be listed here once passed.

Found something?

Write to hello@castan.ai with "security" in the subject. Good-faith research that avoids other customers' data and gives us reasonable time to fix the issue is welcome and will never be met with legal action.

Operator
OCULI OMNIUM SRL, societate cu răspundere limitată (SRL)
Registration
CUI 52198491 · Registrul Comerțului J2025054313009 · capital social 200 lei
Registered office
Intr. Gheorghe Simionescu 19 Ap. B26
VAT
The company is not registered for VAT (small-enterprise exemption, art. 310 Cod fiscal), so prices are final and include no VAT.
Licences
None required for this activity. The service is delivered online; there are no delivery costs.
Consumers
Complaints go to hello@castan.ai first. If we cannot settle one, you may turn to ANPC (Bd. Aviatorilor 72, București, 021 9551, anpc.ro) and to its alternative dispute resolution service, SAL: reclamatiisal.anpc.ro.
Businesses
Business customers are not consumers; the consumer remedies and the right of withdrawal do not apply to them.
ANPC, Soluționarea alternativă a litigiilor

Terms · Privacy · Security

Security, Castan