Activation is temporarily unavailable. Refresh this page to retry.
Menu

SECURITY & TRUST

Trust starts with the claims we do not make.

This page records the Castia-specific evidence available for public reliance. Missing proof stays unavailable instead of inheriting a generic security, privacy, certification, or residency promise.

Public scope
Castia website · English
Last reviewed
28 July 2026
Review cadence
Monthly and on material change

PUBLIC TRUST LEDGER

Evidence status, owner, and date in one place.

“Not verified for public use” means the website cannot support that claim today. It is not a statement that the underlying control is absent.

Data flow, subprocessors, and models

Not verified for public use

No Castia-specific public data-flow diagram or approved list of processors, model providers, and transfer boundaries is available. Buyers should not infer one from circuly material.

Evidence owner
Castia engineering
Last reviewed
28 July 2026

Retention and deletion

Not verified for public use

No Castia-specific public retention schedule, deletion timetable, or backup-deletion statement is approved. Product evaluation must treat those terms as unconfirmed.

Evidence owner
Castia engineering and circuly legal
Last reviewed
28 July 2026

Tenant isolation and access controls

Not verified for public use

The website does not publish a reviewed technical control statement for tenant isolation, privileged access, authentication, or authorization. No assurance should be inferred.

Evidence owner
Castia engineering
Last reviewed
28 July 2026

Human approval and auditability

Public product boundary

Public product pages describe human review before an exact outreach batch is approved. A separate technical assessment of enforcement, event coverage, and audit-log retention is not yet published.

Evidence owner
Castia product and engineering
Last reviewed
28 July 2026

Residency options

Not verified for public use

No Castia-specific residency region or customer-selectable hosting option is published. Residency must be confirmed in writing for the exact product scope before reliance.

Evidence owner
Castia engineering and circuly legal
Last reviewed
28 July 2026

Incident and security contact

Published contact route

Security concerns and suspected incidents can be sent to [email protected] with “Castia security” in the subject. This contact route does not imply a published response-time commitment.

Evidence owner
circuly GmbH management
Last reviewed
28 July 2026

Certification and assessment status

No public certification

No Castia certification is published. The site does not claim a Castia-specific ISO, SOC, penetration-test, availability, or independent assessment status.

Evidence owner
Castia security review
Last reviewed
28 July 2026

Legal documents and product scope

Scope confirmation required

The linked privacy, terms, and DPA pages are circuly GmbH documents. They support evaluation of the legal entity but do not by themselves establish Castia product coverage; confirm the applicable product and processing scope in writing.

Evidence owner
circuly legal
Last reviewed
28 July 2026

SENSITIVE-DATA BOUNDARY

Public signals are not permission for sensitive-data work.

Sensitive-data workflows are not publicly supported.

Insurance and M&A examples stay within public-source research and explicit human decision boundaries. A campaign that requires policy records, confidential deal information, special-category data, or another sensitive source remains unavailable until its data flow, controls, legal basis, and operating evidence are reviewed for that exact use.

DOCUMENT SCOPE

Legal entity context is not product assurance.

These are circuly GmbH documents. They do not by themselves establish Castia product coverage; confirm the exact entity, service, processing role, and version that would apply.

Security contact

[email protected]

Published review cadence

Monthly, and after any material system change.
Next scheduled review: 28 August 2026.