Security
Security at Calenta
Calenta connects your Salesforce to Claude so your team can work with donor data in plain English. We’re built on Cloudflare, Anthropic, and Salesforce, and we take the sensitivity of donor information seriously. Here’s how we handle your data.
How Calenta accesses your data
- Scoped, per-user access. Calenta connects through Salesforce’s standard OAuth and can only see the records your own Salesforce permissions already allow — never more.
- Your records stay in your CRM. Calenta runs live queries and returns answers; it does not bulk-export or copy your donor database out of Salesforce.
- You stay in control. Disconnect any time, and Calenta’s access ends.
Encryption
- In transit: TLS on every connection — between Claude, Calenta, Salesforce, and storage.
- At rest: all stored data is encrypted at rest by default (Cloudflare R2 and KV, AES-256) — org context, uploaded documents, and connection tokens.
AI & your data
- Never used to train AI models. Donor data is processed through Anthropic’s commercial API, whose terms do not use your inputs for training.
- Data minimization. Only the data needed to answer a given request is sent to the model.
Storage & retention
| Data | Where | Retention |
|---|---|---|
| Live query results | Not stored | Returned to you, not persisted |
| Derived outputs (briefs, reports) | Your isolated storage | Deletable on request |
| Documents you upload | Your isolated storage | Deletable on request / offboarding |
| Usage telemetry | Encrypted store | Anonymous only — no donor data — auto-deleted after 30 days |
| Connection tokens | Encrypted store | Removed on disconnect |
Tenant isolation. Each organization’s data is isolated. We never share data across organizations, and we never sell it. Telemetry is anonymous — donor names, emails, query contents, and giving data are never written to it.
Sub-processors
| Provider | Role | Donor data? |
|---|---|---|
| Anthropic | AI model (Claude) | Yes — processes; no training |
| Cloudflare | Hosting, storage, edge | Yes — encrypted storage |
| Salesforce | Your source CRM | Your own system |
| Vercel | Site / portal | No |
| Clerk | Account sign-in | No |
| Stripe | Billing | No |
| Resend | Transactional email | No |
Compliance
Calenta is an early-stage product. We’ve built our foundation to formal-audit standards — scoped access, encryption, tenant isolation, data minimization, and retention limits — and will pursue SOC 2 when our customers’ requirements call for it. We’re glad to complete security questionnaires and sign a DPA.
Security questions or a review request? Email joe@calenta.ai — we’ll respond quickly and candidly.