Security & Compliance

Built to meet the world's
strictest requirements.

CampanaOne is engineered from the ground up to comply with data protection and security regulations across every region we operate in. We treat compliance not as a checkbox, but as a continuous engineering discipline.

Our Position on Compliance

CampanaOne adheres to the security and data protection requirements of every jurisdiction in which we operate or where our customers' contacts reside. Our engineering practices, infrastructure choices, data access policies, and employee training programmes are all designed to meet β€” and in most cases exceed β€” the requirements of applicable regulations worldwide.

We may or may not choose to pursue formal third-party certification against specific standards. Certifications require significant and ongoing investment that we believe is better directed toward actual security improvements. However, our ability and commitment to comply with the underlying requirements is absolute and unconditional.

Where a regulation requires a formal certification as a prerequisite for doing business, we will pursue that certification. In all other cases, we self-assess rigorously and make our practices available for customer review during procurement.

Global Data Protection Regulations

We follow the requirements of the following frameworks, and monitor emerging legislation in every market we serve.

πŸ‡ͺπŸ‡Ί
GDPR
European Union

General Data Protection Regulation. Governs the processing of personal data of EU residents. We operate lawful basis, data minimisation, right-to-erasure, and data portability mechanisms throughout our platform.

πŸ‡ΊπŸ‡Έ
CCPA / CPRA
California, USA

California Consumer Privacy Act and its enhancement, the California Privacy Rights Act. We support opt-out of sale, right to deletion, and right to know for California residents whose data is processed through our platform.

πŸ‡¦πŸ‡ͺ
UAE PDPL
United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Our UAE region deployment (me-central-1) ensures data residency within UAE borders and complies with TDRA requirements.

πŸ‡¬πŸ‡§
UK GDPR & DPA 2018
United Kingdom

Post-Brexit UK data protection framework administered by the ICO. Our primary infrastructure in eu-west-2 (London) keeps UK customer data within the UK, supporting data localisation requirements.

πŸ‡¨πŸ‡¦
PIPEDA
Canada

Personal Information Protection and Electronic Documents Act. We support accountability, consent, limiting collection, and individual access principles for Canadian residents.

πŸ‡§πŸ‡·
LGPD
Brazil

Lei Geral de ProteΓ§Γ£o de Dados. Brazil's comprehensive data protection law modelled on GDPR. We apply equivalent data subject rights and processing principles for Brazilian residents.

πŸ‡ΈπŸ‡¬
PDPA
Singapore

Personal Data Protection Act. We support consent, purpose limitation, and data breach notification requirements for Singapore-based organisations and their contact data.

πŸ‡ΏπŸ‡¦
POPIA
South Africa

Protection of Personal Information Act. We apply the 8 conditions for lawful processing β€” accountability, processing limitation, purpose specification, further processing, information quality, openness, security, and data subject participation.

πŸ‡ΈπŸ‡¦
PDPL / NDMO
Saudi Arabia

Saudi Arabia's Personal Data Protection Law and National Data Management Office requirements. Our UAE region deployment serves Saudi customers with data handling that meets NDMO requirements for most use cases.

Technical Security Practices

How we engineer, build, and operate CampanaOne to protect your data.

Encryption

  • β€’ TLS 1.3 in transit (TLS 1.2 minimum), HSTS enforced
  • β€’ AES-256 at rest via AWS KMS on all Aurora databases
  • β€’ Application-level envelope encryption for PII fields (phone, email)
  • β€’ S3 buckets encrypted with SSE-KMS; Object Lock on audit logs (WORM)
  • β€’ Secrets stored exclusively in AWS Secrets Manager β€” never in code or environment variables

Authentication & Access

  • β€’ AWS Cognito with JWT tokens (15-min access / 7-day refresh with rotation)
  • β€’ MFA enforced for Root Administrator accounts
  • β€’ Role-Based Access Control (RBAC) on every API endpoint
  • β€’ Principle of least privilege on all IAM roles
  • β€’ SSO / SAML 2.0 support for enterprise customers

Audit & Logging

  • β€’ Every user action logged to an immutable S3 audit trail (Object Lock / WORM)
  • β€’ CloudWatch centralised logging with anomaly detection
  • β€’ AWS GuardDuty for threat detection and Security Hub for posture management
  • β€’ Webhook HMAC signature verification for all inbound provider callbacks
  • β€’ CDR (Call Detail Records) maintained for every communication event

Secure Development

  • β€’ OWASP Top 10 addressed in every development cycle
  • β€’ Input validation and parameterised queries throughout β€” no raw SQL
  • β€’ Dependency scanning and security patches applied promptly
  • β€’ Infrastructure as Code (AWS CDK) β€” no manual console changes in production
  • β€’ GitHub Actions CI/CD pipeline with automated security scanning

Infrastructure & Availability

  • β€’ Multi-region AWS deployment (UK, UAE, Bahrain, Frankfurt)
  • β€’ Aurora Serverless v2 PostgreSQL β€” Multi-AZ, KMS encrypted
  • β€’ Aurora Global Database for UAEβ†’Bahrain DR (sub-second RPO)
  • β€’ Serverless Lambda architecture β€” no persistent servers to patch
  • β€’ SQS Dead Letter Queues for reliable message processing

People & Training

  • β€’ Security awareness training for all staff handling customer data
  • β€’ Background checks for employees with production access
  • β€’ Documented data handling procedures and incident response plan
  • β€’ Need-to-know access model β€” production access granted only to those who require it
  • β€’ Regular internal security reviews and tabletop exercises

Standards We Align With

Our practices are designed to be consistent with these internationally recognised frameworks.

ISO 27001 SOC 2 Type II OWASP Top 10 NIST CSF CIS Benchmarks AWS Well-Architected GDPR Article 32

Security questions before you buy?

Our team will walk you through our security architecture, data flows, and answer your procurement questionnaire.

Book a Security Review