Privacy Policy

Effective: August 26, 2026 · Calera Computing, Inc. · Contact: support@caleralabs.com

This Privacy Policy explains how Calera Computing, Inc. ("Calera Labs", "we", "us", "our") collects, processes, protects, and handles data across our hosted APIs, software development kits (SDKs), Model Context Protocol (MCP) servers, and user consoles — including FinanceSec, Infinite Context (ICX), and the Universal Dashboard (dashboard.caleralabs.com).

Zero Foundation Model Training Guarantee: Calera Labs does not use customer queries, ingested documents, memory spaces, custom ontologies, or API payloads to train public foundation models, distill third-party statistical weights, or share data across tenant boundaries. Your proprietary data remains strictly isolated to your organization.

1. Information We Process

2. Data Sovereignty & Memory Isolation

Infinite Context (ICX) and FinanceSec operate with strict tenant isolation. Ingested documents and crystallized memory nodes are partitioned by tenant organization identifier (X-CaleraLabs-OrgId). No tenant's memory space or query history is accessible by or merged into another tenant's workspace or any shared statistical model.

3. AI Agents, Swarms & Model Context Protocol (MCP)

Calera Labs provides deterministic factual computation, memory topology, and verified data grounding. When you connect autonomous agents, IDE assistants (e.g., Cursor, VS Code, Claude Desktop), or multi-agent swarms via our MCP servers (e.g., financesec-mcp, icx-mcp):

4. User-Controlled Telemetry & Privacy Preferences

We respect client data sovereignty and provide granular privacy controls directly within your account:

5. Data Retention & Self-Service Deletion

6. Subprocessors & Infrastructure

We partner exclusively with enterprise-grade infrastructure providers that adhere to stringent security standards (SOC 2, ISO 27001):

7. Security & Cryptographic Integrity

All data in transit is encrypted using modern Transport Layer Security (TLS 1.3). Sensitive secrets and BYOK credentials are protected with Cloud KMS envelope encryption. Our container runtimes use minimal distroless base images with non-root execution profiles, eliminating legacy shell vectors. Factual responses include cryptographic SHA-256 verification hashes for end-to-end tamper detection.

8. Global Privacy Rights (GDPR & CCPA/CPRA)

Regardless of your geographic location, you enjoy full sovereignty over your personal data:

9. Changes & Contact

We may update this Privacy Policy to reflect evolving technical capabilities or statutory requirements. When changes occur, the effective date at the top of this page will be updated. For questions, compliance reviews, or Data Processing Agreements (DPAs), contact our privacy team at support@caleralabs.com.