‹ Calluna

Trust

Last updated September 11, 2026

This page says, in plain words, what happens to a business's content inside Calluna and what we can and cannot promise. Every claim here has a written basis we will show to any customer who asks, and the Privacy Policy is the binding version.

Where Calluna runs

In the United States. Each business gets its own isolated instance: its own agent process and its own row-scoped data. One customer's content is never pooled with another's, and nothing in one instance can read another.

What is encrypted

The keys the social platforms give us for your accounts are encrypted at rest with a key the instance holds, and we never receive or store your platform passwords. Everything travels over HTTPS. Access to production systems is limited to the people who run the service.

Sign-in

Sign-in is handled by a dedicated identity provider we host. Passwords never reach Calluna's own code. Two-factor sign-in is available, and we turn it on for every account owner before their first day. A person who is locked out can be recovered by us after we confirm who they are.

What the model sees, and what it never does

Drafts are written by a language model that runs privately: either on machines we operate, or through a provider whose contract forbids training on customer content and requires zero retention. The model sees only the facts you gave Calluna about your business, your voice rules, and up to a handful of your own approved posts. Your content is never used to train, fine-tune, or improve any model, ours or anyone else's. Calluna learns your voice by keeping a profile you can read and edit, not by changing a model.

A person approves every post

Nothing is published, replied to, or scheduled without a person on your team approving it in Calluna. The approval is bound to exactly what was on the screen; if the text changed in between, the approval is refused and the refusal is recorded.

The record

Every action in your instance, including every approval, refusal, and publish, lands in a permanent record that can be checked in your browser and downloaded at any time. Each entry carries a receipt derived from the one before it, so if any entry were ever altered the record would show it. It is tamper-evident, which means alterations are visible, not impossible. It is not a substitute for a backup, and it does not hold anything a social platform gave us about your account.

Your data, in and out

You can export everything from inside Calluna at any time. Deleting your data is described on the data deletion page: we finish within 30 days, including backups.

What we do not have yet

No third-party security audit and no SOC 2 report. During the pilot the service runs without a formal uptime commitment. We will say so on this page when either changes.

Reporting a vulnerability

Email security@hicalluna.com. We will acknowledge within two business days, tell you what we found, and credit you if you want to be credited. Please do not test against accounts that are not yours.

Contact

Calluna Labs
admin@hicalluna.com