Security & Compliance

Security at ANCI.

Built on the engine 128 enterprises trust since 2020. SOC 2 Type II audit in progress, Q4 2026.

Our security posture, at a glance.

Encryption

AES-256 at rest, TLS 1.3 in transit. Encryption keys managed via AWS KMS.

Compliance

SOC 2 Type II in progress, Q4 2026. GDPR-compliant. HIPAA BAA available.

Privacy

Customer data isolated by tenant. EU data residency available. Zero calendar event content stored.

Access

OAuth-based authentication. No passwords stored. Revocable any time from your admin console.

Compliance and certifications.

Where we are with formal certifications, what's available now, and what's available on request.

FrameworkStatusAvailable
SOC 2 Type II Audit in progress, Q4 2026 Type I report and pre-audit questionnaire available now
GDPR Compliant DPA available for immediate download (no sign-in required)
HIPAA BAA available for healthcare customers BAA available on request
EU Standard Contractual Clauses Module 2 (Controller to Processor) implementing EU Decision 2021/914/EU Automatically included with DPA for EU customers
Penetration testing Annual third-party tests Summary available under NDA
If your security review process requires SOC 2 Type II to proceed: Type II report is on track for Q4 2026. In the interim, we provide Type I report, pre-audit security questionnaire (44 questions, SIG Lite / CAIQ format), penetration test summary, and a scheduled security call with our team. Most enterprise security teams find this sufficient to move forward with a deployment pilot.

How we handle your data.

Where data lives, how long we keep it, and who else touches it.

Data residency

Customer data is hosted on AWS, US-East primary region. EU data residency available for European customers on request. Customer data is isolated by tenant; we cannot read across customer boundaries.

Data retention

Active scheduling data retained for the duration of your subscription. Audit logs retained for 12 months. On termination, all customer data is deleted within 30 days unless a longer retention period is contractually required.

Sub-processors

AWS (hosting and storage), Stripe (subscription billing), and Anthropic (Claude API for natural language understanding). Full sub-processor list available on request at security@meetanci.com.

Access controls

Authentication is OAuth-based. We never see, store, or transmit user passwords. Access is granted by your IT administrator and can be revoked at any time from your standard admin console.

Documents and resources.

Most legal and compliance documents are available for immediate download. No sign-in, no sales conversation required.

Download · No sign-in

GDPR Data Processing Agreement

GDPR-compliant DPA defining how we process personal data on your behalf. Required for EU customers. Covers controller/processor roles, sub-processors, and data subject rights.

Download PDF →
DPA v1.0 · April 2026
Download · No sign-in

Vendor Security Questionnaire

Pre-filled answers to 44 standard enterprise IT security questions. SIG Lite / CAIQ format. Covers governance, data handling, security controls, infrastructure, compliance, third-party risk, and access management.

Download PDF →
v1.0 · April 2026
Download · No sign-in

Data Retention & Deletion Policy

Defines exactly what data we store, for how long, and how it is deleted. Confirms calendar event content is never stored. Covers erasure requests and deletion certification.

Download PDF →
v1.0 · April 2026
For IT teams

IT Administrator Setup Guide

Technical reference for IT administrators: exact OAuth scopes, what we access and what we don't, step-by-step approval and revocation instructions for Google Workspace and Microsoft 365.

View setup guide →
Updated continuously
Trust Center

Live Trust Center

Real-time security posture, certifications, and compliance status. Hosted at trust.teamcal.ai (ANCI is operated by Calndr Inc., the same legal entity that operates TEAMCAL AI).

Visit Trust Center →
Updated continuously
Available on request

Master Service Agreement · SLA · BAA · EU SCC

MSA, 99.9% uptime SLA, HIPAA Business Associate Agreement, and EU Standard Contractual Clauses are available on request. We respond within one business day.

Request document →
Response within 1 business day

Questions from your legal or security team?

We respond to enterprise legal, security, and procurement queries within one business day. Our team is happy to get on a call with your IT or InfoSec team.

Security questions

Architecture, controls, certifications

Questionnaires, Type I reports, penetration test summaries, sub-processor lists.

security@meetanci.com →
Legal & compliance

Contracts, DPAs, BAAs, SCCs

Signed copies, custom contract terms, MSA negotiation, BAA execution.

legal@meetanci.com →
Security call

Live conversation with our team

30-minute call with our team for security reviews requiring direct engagement.

Request a call →
ANCI is a product of Calndr Inc., the legal entity that has operated TEAMCAL AI since 2020. Our legal and compliance documents are issued by Calndr Inc. and apply to both products. Customer data, contracts, and service obligations are governed by the same legal framework that has served 128 enterprises across 90 countries. Calndr Inc., 855 Maude Ave, Mountain View, CA 94043, USA.