Security & Compliance
Security, governance, and compliance built for the modern enterprise
Today’s IT leaders don’t just need a secure integration platform. They need one that helps them move faster while keeping control. Celigo builds security, governance, and compliance into every layer of the platform, so you can scale automation with confidence.
The leading iPaaS, powering leading brands
Every layer, covered
Security built into every layer of the platform
From data movement to access control to AI-driven automation, security is not an add-on. It is how the platform works.
Data protection
Celigo is committed to secure, private, and compliant data movement across systems — protecting both your data and the applications it moves through. The platform does not persistently store processed data. In the rare cases where temporary storage is necessary to complete a workflow, data is encrypted at rest using AES-256 and stored within Celigo’s primary application infrastructure on Amazon S3.
Every transaction is encrypted in transit and at rest (TLS 1.2+, AES-256), and credentials are tokenized — never stored in plain text. For payment card data, Celigo recommends upstream tokenization, in line with PCI-DSS best practices. Regional data hosting — including dedicated Private Cloud options — is available across North America, the EU, Canada, and Australia.
Access control: RBAC, SSO, and separation of duties
Multiple levels of access — Account owner, Admin, Manage all, Monitor all, and Custom — along with OIDC-based SSO, MFA, and environment-level controls.
Secure connectivity
For systems behind your firewall, Celigo’s on-premise agent provides secure connectivity without exposing internal systems to the public internet.
Audit trails and monitoring
Every user action is logged across environments — who changed what, when, and from where. Audit logs are retained for at least one year, with longer retention available on upgraded subscriptions.
AI agent security
The same governance model — roles, audit trails, and runtime guardrails — extends to Celigo’s AI agents and MCP servers, so AI-driven automation isn’t a separate, less-governed system.
Certifications
Certifications and regulatory compliance: What to verify before you approve an iPaaS vendor
Before approving an integration platform for enterprise use, IT and security teams typically need answers to a few core questions: What’s actually certified, versus just “ready”? Does it cover the deployment model you’re using? And can you verify it yourself, rather than taking a vendor’s word for it?
SOC 2 Type II
Verified controls for security and availability
SOC 1 Type II
Verified controls relevant to financial reporting
GDPR / DPF / CCPA
US, EU, UK, and Swiss data privacy compliance
HIPAA-readiness
Healthcare data privacy and security. BAA required
FERPA-readiness
Compliance support for educational institutions
Actively pursuing: ISO/IEC 27001 and ISO/IEC 42001 certification, targeted for Q1 2027.
Celigo does not currently hold FedRAMP or PCI DSS certification. Customers with cardholder data tokenize it upstream, and Celigo’s infrastructure runs on FedRAMP-authorized cloud regions to support customers who require that posture.