Need-to-know access
Time-boxed, role-scoped grants with accountable identities.
TRUST CENTER
Castler is evaluated by regulated institutions before it is trusted with critical software. This is the control surface they examine.
SECURITY ARCHITECTURE
Encrypted ingress
TLS channels · repository allowlist
Integrity sealing
SHA-256 fingerprint · version identity
Segregated storage
Per-beneficiary isolation
Region replication
Residency-aware copies
Time-boxed access
MFA · least privilege
Audit trail
Every action linked end-to-end
ISO 27001
Information security management
SOC 2 Type II
Security and availability controls
PCI DSS
Payments-grade controls
Regional
Hosting and verification options
SECURITY CONTROLS
Time-boxed, role-scoped grants with accountable identities.
Regional placement with return or verified destruction on exit.
Control evidence aligned to the current assurance package.
Encryption in transit and at rest with customer separation.
Release fingerprints, SBOMs and immutable version history.
Every deposit, access, verification and release is recorded.
One evidence chain—from repository access to controlled release
SECURITY PRACTICES
AES-256 at rest and TLS 1.2+ in transit, with customer-managed keys available for regulated deployments.
Role-based access, SSO/SAML, MFA for privileged operations, and least privilege by default.
Every deposit, build, verification, and seal is logged and tied to an accountable identity.
A vetted, minimal set of sub-processors with customer notice before material changes.
Rebuild and verification can run in the selected region and cloud to support jurisdiction and residency needs.
Castler is built to the recoverability standard it asks critical vendors to meet.
CERTIFICATION AND CONTROL MATRIX
WHERE DOES MY CODE GO?
The deployment model can be configured around the selected cloud, region, access model, and jurisdiction. Your Proof of Recovery is signed against that controlled environment.
Trust is a property of the whole system
Custody, access, build environments, audit trails, regional controls, and engineer accountability are designed as one evidence chain.
SECURITY PACKAGE
Request Castler’s current certifications, sub-processor information, DPA, and architecture brief for your jurisdiction.
Book a 15-min briefing