How Celigo protects data in motion and at rest
Integration platforms move some of your most sensitive business data: customer records, financial transactions, operational events, credentials, and system updates.
That makes data security a core requirement for enterprise iPaaS. Your integration platform needs to help protect data while it moves between systems, limit unnecessary storage, secure temporary data needed for retries and error handling, and support regional and regulatory requirements.
Celigo is designed with those requirements in mind. The platform supports encryption in transit and at rest, protects stored credentials, provides configurable retention for supported log and error data, and offers regional hosting options through Celigo Private Cloud for organizations with data residency or compliance requirements.
Encryption in transit and at rest
Celigo uses encryption to help protect data while it moves through the platform and while certain operational data is temporarily stored.
- Data in motion inside Celigo’s AWS VPC is encrypted using TLS 1.2 or better.
- Data temporarily stored in AWS is encrypted using AES-256.
- Stored credentials are encrypted using AES-256 or PBKDF2-based protections before being stored for subsequent integration use.
Protecting stored credentials
Customers provide credentials for the applications and endpoints that Celigo connects to. Those credentials are protected before being stored for subsequent integration use.
Celigo encrypts sensitive credentials stored in the platform using AES-256. The encryption key itself is derived using PBKDF2 — a password-based key derivation function used to generate the AES-256 key, not an alternative or competing encryption standard.
Endpoint security remains a shared responsibility. Celigo recommends that customers use HTTPS endpoints protected with TLS 1.2 or better. Connecting to plain HTTP, or to an HTTPS endpoint using a TLS version below 1.2, can weaken the security of that segment of an integration.
What this means: Celigo protects data as it moves through the platform, while customers remain responsible for ensuring that source and destination systems expose secure endpoints and use appropriate encryption.
Data masking and sensitive-data protection
Encryption protects data from unauthorized access in transit and at rest. Masking provides an additional layer of protection by limiting the sensitive information exposed during processing or logging.
Celigo currently documents masking in two specific contexts; there is no general-purpose payload-masking feature beyond these.
PII masking with Celigo guardrails
Celigo PII guardrails can detect configured categories of personally identifiable information and return a structured result that flags whether PII was found. When configured, the output can include a masked or safe representation of detected PII.
Guardrails do not automatically modify the original record. They evaluate the record and return structured output that downstream flow logic can use for routing, review, skipping, retrying, or exception handling.
Celigo guardrails can be used before or after AI agent activity, or anywhere in a traditional flow or API endpoint where supported.
Data masking in API Management
Celigo API Management Advanced provides a Data Logging Masking policy for v2 API definitions, which can conceal selected sensitive values in API Management logs specifically.
This control should not be described as universal platform-wide payload masking — it applies to logs and is an Advanced-tier capability.
Tokenization and payment card data
For payment card information, Celigo recommends that cardholder data be tokenized before it enters an integration and that its use be approved through the customer’s PCI DSS governance process.
Celigo is not PCI DSS certified. Celigo does not provide a publicly documented, native, general-purpose tokenization feature. Tokenization is the customer’s responsibility and should be performed before cardholder data enters the integration.
Minimal data storage by design
Celigo is an integration platform, not a data warehouse. By default, the platform processes data so it can move between applications while supporting operational requirements such as observability, error recovery, and retries. In-process data is deleted when processing completes successfully.
For customers who need to intentionally retain data, Celigo Storage provides a managed option for long-term storage. This is opt-in, not the platform’s default behavior, and it’s designed to support use cases like building complex integration patterns more efficiently and exposing stored data in a controlled way for further use, including analysis by AI agents.
The platform processes data so it can move between applications while supporting operational requirements such as observability, error recovery, and retries. In-process data is deleted when processing completes successfully.
When operational data must be retained for logging, troubleshooting, error recovery, or retry, it follows the applicable retention settings.
Log and error retention
Celigo gives customers control over how long supported log and error data is retained, based on their subscription.
The default retention period is 30 days. Depending on the subscription, customers can opt for longer retention periods of 60, 90, or 180 days. Retained data can include flow run history, error details, request and response data associated with errors, and supported debug logs.
Each flow can also be configured not to retain the data it processes, helping organizations reduce the amount of sensitive business data available for troubleshooting when appropriate.
Log retention is different from audit-log retention
Operational log and error retention should not be confused with audit-log retention. Execution data, error and retry information, temporarily retained PII, and audit records serve different purposes and can have different retention periods.
Temporary PII handling during connection failures
Celigo’s handling of personally identifiable information is designed to limit unnecessary storage.
When PII from connections and flows must be retained because a connection is unavailable, the in-flight data is written to an Amazon S3 bucket using AES-256 encryption and timestamped. The data can be retained for up to 30 days to support error analysis and retry. If the affected flow completes successfully within that window, the retained information is deleted.
This description applies specifically to PII retained for connection failure, error recovery, and retry scenarios, not to every piece of PII processed successfully by Celigo.
Handling regulated and sensitive data
Different categories of sensitive information require different technical, contractual, and governance controls.
Payment card information and PCI DSS
Celigo is not PCI-DSS certified. Customers are advised not to integrate cardholder data unless it has first been tokenized and its use approved through the customer’s PCI-DSS governance processes.
GDPR and Data Processing Agreements
Organizations processing personal data covered by EU or UK data-protection requirements should ensure the appropriate contractual and governance controls are in place. Celigo’s security guidance instructs customers processing EU or UK resident data to have an applicable Data Processing Agreement in place, and to collect and integrate only the minimum personal data necessary.
Customers can request a DPA by contacting [email protected].
HIPAA
Celigo describes the platform as HIPAA-ready, though not HIPAA-certified. Customers should not integrate ePHI unless a Business Associate Agreement has been executed between the customer and Celigo.
What this means: Celigo can support regulated integration workflows, but organizations still need appropriate agreements, data-minimization practices, endpoint protections, and internal governance before sensitive data enters an integration.
Infrastructure and access security
Data protection also depends on the infrastructure and access controls surrounding the integration platform.
Production and testing environments are completely segregated, and customer data is not used in QA or developer testing. Celigo also maintains annual penetration testing, recurring vulnerability testing, remediation processes, and a HackerOne bug bounty program engaging independent security researchers.
Access controls add additional layers of protection: web application access uses authenticated accounts with one-way password hashing, and API access uses bearer tokens. Web and API communications use HTTPS/TLS.
Data residency with Celigo Private Cloud
Some organizations have geographic, regulatory, security, or operational requirements that go beyond shared cloud infrastructure.
Celigo Private Cloud provides a private, isolated Celigo platform instance with dedicated resources. It is designed for organizations that need additional control, data-residency options, dedicated infrastructure, or support for specialized compliance requirements.
Customers can select a hosting location during onboarding. The detailed location list appears in the current Introduction to Celigo Private Cloud documentation.
Choosing an appropriate region can help organizations address geographic data-residency requirements and may also reduce latency for nearby users and systems.
Celigo Private Cloud encrypts data at rest and in transit using strong encryption controls. Specific networking and encryption architecture can be confirmed with Celigo based on the customer’s deployment requirements.
Standard hosting regions
Separate from Private Cloud, Celigo’s standard hosting is available in the US, the EU, Australia, and Canada. Each region gets a dedicated domain, with data, credentials, and integrations kept in-region and no cross-region access. Australia is hosted on AWS Asia Pacific (Sydney); Canada is hosted on AWS Canada (Central), the same enterprise-grade AWS infrastructure that powers Celigo globally.
Private Cloud compliance and secure connectivity
Celigo Private Cloud is designed to support enterprise security and compliance needs, including SOC 2 Type II, ISO/IEC 27001, GDPR, and CCPA, along with encryption at rest and in transit, role-based access control, audit logging and monitoring, and incident-response support.
For industry-specific requirements such as HIPAA or PCI DSS, Celigo can tailor a dedicated instance to help address those needs. This tailored configuration support does not represent formal certification or a validated PCI environment. The exact scope should be confirmed contractually with Celigo.
For secure connectivity, Celigo Private Cloud supports VPN connectivity and IP whitelisting. Celigo also recommends layered controls such as VPN, IP whitelisting, and SSO where appropriate.
What this means for regulatory compliance
Celigo provides technical controls to support regulatory compliance — including encryption, masking, regional hosting, access controls, logging, and configurable retention. These features don’t guarantee compliance on their own; customers remain responsible for configuration, endpoint security, data minimization, governance, and required agreements.
See how Celigo secures enterprise integration
Data protection is one part of enterprise iPaaS security. Celigo also supports identity and access controls, audit logging, secure connectivity, environment controls, API security, and AI governance.