Security & Data Handling
Last updated: August 2026
A short reference for IT and security teams reviewing Caleta products during procurement. It covers the Caleta Private AI Appliance and the Caleta Cost Review SaaS application, and explains how to report a vulnerability. For full detail, see the Privacy Policy and Terms of Service.
Caleta Private AI Appliance security posture
The Caleta Private AI Appliance is a virtual machine image you deploy into your own Azure subscription. It is built to run privately, with no inbound access required.
- Everything binds to localhost by default. Nothing is published to a network unless you choose to
- The host firewall is default-deny on inbound traffic
- A fresh inference API key is minted on every boot and never leaves the VM unless you copy it
- Optional TLS exposure of the chat interface is available via Let's Encrypt, with source-IP restriction so you decide who can reach it
- Trusted Launch with Secure Boot is supported and is the deployment default
- No inbound access is required for the appliance to operate; it can run fully air-gapped once its models are downloaded
- Registering an email address for update notifications is optional and opt-in. The appliance is fully functional without it, and no email address is collected unless you enter one. See the Privacy Policy for what is stored and how to unsubscribe
The sections below cover the Caleta Cost Review SaaS application.
Data residency
- All customer data (cost data, scan results, account information) is stored exclusively in the UK South Azure region
- The marketing website (caleta.io) is delivered via a global CDN; only static page content passes through the CDN, no customer data
Encryption
- In transit: TLS 1.2+ for all connections to and from the service
- At rest: AES-256 in the underlying Azure database
Access controls
- Role-based access control (RBAC) on all administrative interfaces
- Multi-factor authentication required for all Caleta personnel
- Customer data access is limited to Caleta personnel performing your review
Permissions requested in your tenant
- Reader (built-in role) – resource inventory via Azure Resource Graph
- Cost Management Reader (built-in role) – cost data via the Cost Management API
- Advisor recommendations – read-only via the Advisor API (covered by Reader)
All access is read-only. Caleta cannot make changes to your Azure environment.
What we do NOT request
- No write access to any resource
- No data plane access (no VM disks, no database contents, no storage blob contents)
- No directory access – no reading other users, groups, or sign-in logs (we read only the signed-in user's own name and email, via Microsoft Graph
User.Read, to sign you in) - No Key Vault access
Sub-processors
- Microsoft Azure (UK South) – hosting, database storage, AI-assisted analysis via Azure AI Foundry, and read-only Cost Management API access to the subscriptions you authorise
- Microsoft 365 – transactional email delivery and customer communication
- Cloudflare – DNS and secure tunnel for the API endpoint
See the Privacy Policy for the full sub-processor terms.
Customer controls
- Revoke the app's access at any time in Microsoft Entra (Enterprise applications) – access stops immediately
- Request data export or deletion at any time
- We retain your data as described in our Privacy Policy and delete it whenever you request – within 30 days
Incident response
Suspected security incidents involving customer data should be reported to privacy@caleta.io. We will acknowledge receipt within one business day and provide updates as the investigation progresses.
Vulnerability disclosure
We welcome reports from security researchers acting in good faith.
- How to report: email privacy@caleta.io with enough detail for us to reproduce the issue
- What to expect: we aim to acknowledge your report within two business days and will keep you updated as we investigate. We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to remediate before public disclosure
- Scope: the Caleta Private AI Appliance image and the Caleta attestation and catalogue service at
cio-web-api.caleta.io
Related Policies
For the legal and contractual position, please review the Privacy Policy and Terms of Service.