HIPAA, ISO 27001, SOC 2 compliant scheduling
Best-in-class scheduling, built for compliance.
HIPAA, ISO 27001, and SOC 2 protection—powered by Cal.com’s privacy-by-design platform.
Information security with every booking
Your scheduling system shouldn’t be the weakest link in your compliance stack. Cal.com’s privacy-by-design architecture gives you the confidence of HIPAA, SOC 2 Type II, ISO 27001, CCPA, and GDPR compliance, without sacrificing usability.






01
SOC 2 Type II
Independently audited annually and continuously monitored for security, availability, and confidentiality.

02
HIPAA compliance
Patient data secured with encryption, access controls, and signed BAAs. PHI-safe workflows protect privacy.

03
ISO/IEC 27001
A global standard for information security management, ensuring rigorous data protection practices and continuous risk management.

04
GDPR
Compliant with the European Union’s GDPR, safeguarding personal data and user privacy rights.

05
CCPA
Compliant with CCPA. Providing California residents with rights to access, delete, and control their personal information.

06
PCI DSS
We ensure secure payment processing through our trusted partner, Stripe, which is fully PCI DSS compliant.

01
Domain-wide delegation
Simplify setup and ensure compliance across your organization. Cal.com gives administrators centralized control over calendars, bookings, and access.

02
SAML SSO, SCIM provisioning
SAML SSO, SCIM provisioning, and automated workflows give admins full visibility and control from one dashboard.

03
Privacy compliance tools
Role-based access (RBAC), SAML SSO, and configurable data residency options simplify privacy management across multiple regulatory jurisdictions.

03
Encryption and security monitoring
Cal.com encrypts data in transit and at rest, with continuous monitoring and vulnerability management for ongoing protection.

Healthcare & wellness
Manage patient scheduling, telehealth sessions, and client intakes with full HIPAA compliance and automated reminders.
Government & finance
SOC 2 and GDPR–compliant scheduling built with enterprise-grade information security to protect sensitive data.
Sales & GTM teams
Route demo requests, coordinate CSM calls, and manage onboarding on privacy-compliant scheduling infrastructure.
Is Cal.com HIPAA compliant?
Yes. Cal.com offers a HIPAA compliant Enterprise plan that includes a signed Business Associate Agreement (BAA) and features designed to protect PHI, such as encrypted data storage, access logging, and customizable intake workflows.
Is Cal.com SOC 2 certified?
Yes. Cal.com maintains SOC 2 Type II certification, verified through annual independent audits covering security, availability, and confidentiality controls.
How does Cal.com differ from other scheduling tools?
Cal.com was built for organizations, not individuals. It combines enterprise-grade security (SSO, SCIM, audit logs) with the simplicity of a modern calendar app, so scaling secure scheduling across teams is seamless.
Can I restrict data access by team or department?
Yes. Cal.com supports role-based access control (RBAC), sub-team structures, and domain enforcement so only authorized users can access or modify sensitive booking data.
Can I use my own branding and get a custom subdomain?
Yes. You can host your scheduling pages on your own company.cal.com subdomain or fully white label Cal.com under your organization’s brand. Customize colors, logos, and booking pages to create a seamless, branded experience.
What support options are available for Enterprise customers?
Enterprise plans include priority support, dedicated onboarding, and optional service-level agreements (SLAs) to ensure smooth implementation and ongoing success.
Simplify scheduling. Strengthen compliance.
Cal.com gives your organization the freedom to schedule securely, without compromise.















