Our Position on Compliance
CampanaOne adheres to the security and data protection requirements of every jurisdiction in which we operate or where our customers' contacts reside. Our engineering practices, infrastructure choices, data access policies, and employee training programmes are all designed to meet β and in most cases exceed β the requirements of applicable regulations worldwide.
We may or may not choose to pursue formal third-party certification against specific standards. Certifications require significant and ongoing investment that we believe is better directed toward actual security improvements. However, our ability and commitment to comply with the underlying requirements is absolute and unconditional.
Where a regulation requires a formal certification as a prerequisite for doing business, we will pursue that certification. In all other cases, we self-assess rigorously and make our practices available for customer review during procurement.
Global Data Protection Regulations
We follow the requirements of the following frameworks, and monitor emerging legislation in every market we serve.
General Data Protection Regulation. Governs the processing of personal data of EU residents. We operate lawful basis, data minimisation, right-to-erasure, and data portability mechanisms throughout our platform.
California Consumer Privacy Act and its enhancement, the California Privacy Rights Act. We support opt-out of sale, right to deletion, and right to know for California residents whose data is processed through our platform.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Our UAE region deployment (me-central-1) ensures data residency within UAE borders and complies with TDRA requirements.
Post-Brexit UK data protection framework administered by the ICO. Our primary infrastructure in eu-west-2 (London) keeps UK customer data within the UK, supporting data localisation requirements.
Personal Information Protection and Electronic Documents Act. We support accountability, consent, limiting collection, and individual access principles for Canadian residents.
Lei Geral de ProteΓ§Γ£o de Dados. Brazil's comprehensive data protection law modelled on GDPR. We apply equivalent data subject rights and processing principles for Brazilian residents.
Personal Data Protection Act. We support consent, purpose limitation, and data breach notification requirements for Singapore-based organisations and their contact data.
Protection of Personal Information Act. We apply the 8 conditions for lawful processing β accountability, processing limitation, purpose specification, further processing, information quality, openness, security, and data subject participation.
Saudi Arabia's Personal Data Protection Law and National Data Management Office requirements. Our UAE region deployment serves Saudi customers with data handling that meets NDMO requirements for most use cases.
Technical Security Practices
How we engineer, build, and operate CampanaOne to protect your data.
Encryption
- β’ TLS 1.3 in transit (TLS 1.2 minimum), HSTS enforced
- β’ AES-256 at rest via AWS KMS on all Aurora databases
- β’ Application-level envelope encryption for PII fields (phone, email)
- β’ S3 buckets encrypted with SSE-KMS; Object Lock on audit logs (WORM)
- β’ Secrets stored exclusively in AWS Secrets Manager β never in code or environment variables
Authentication & Access
- β’ AWS Cognito with JWT tokens (15-min access / 7-day refresh with rotation)
- β’ MFA enforced for Root Administrator accounts
- β’ Role-Based Access Control (RBAC) on every API endpoint
- β’ Principle of least privilege on all IAM roles
- β’ SSO / SAML 2.0 support for enterprise customers
Audit & Logging
- β’ Every user action logged to an immutable S3 audit trail (Object Lock / WORM)
- β’ CloudWatch centralised logging with anomaly detection
- β’ AWS GuardDuty for threat detection and Security Hub for posture management
- β’ Webhook HMAC signature verification for all inbound provider callbacks
- β’ CDR (Call Detail Records) maintained for every communication event
Secure Development
- β’ OWASP Top 10 addressed in every development cycle
- β’ Input validation and parameterised queries throughout β no raw SQL
- β’ Dependency scanning and security patches applied promptly
- β’ Infrastructure as Code (AWS CDK) β no manual console changes in production
- β’ GitHub Actions CI/CD pipeline with automated security scanning
Infrastructure & Availability
- β’ Multi-region AWS deployment (UK, UAE, Bahrain, Frankfurt)
- β’ Aurora Serverless v2 PostgreSQL β Multi-AZ, KMS encrypted
- β’ Aurora Global Database for UAEβBahrain DR (sub-second RPO)
- β’ Serverless Lambda architecture β no persistent servers to patch
- β’ SQS Dead Letter Queues for reliable message processing
People & Training
- β’ Security awareness training for all staff handling customer data
- β’ Background checks for employees with production access
- β’ Documented data handling procedures and incident response plan
- β’ Need-to-know access model β production access granted only to those who require it
- β’ Regular internal security reviews and tabletop exercises
Standards We Align With
Our practices are designed to be consistent with these internationally recognised frameworks.
Security questions before you buy?
Our team will walk you through our security architecture, data flows, and answer your procurement questionnaire.
Book a Security Review