Enterprise-grade security. Verified by SOC 2.
Cal.com is SOC 2 Type II compliant, independently audited to meet the highest standards for data security and privacy so you can schedule with confidence.

What is SOC 2 and why it matters
SOC 2 is a framework developed by the AICPA to ensure companies handle customer data securely, following five key criteria: security, availability, confidentiality, processing integrity, and privacy.
A SOC 2 Type II certification means Cal.com consistently applies strict security practices, verified through independent audits. This certification gives you peace of mind that your scheduling data is protected and handled with transparency.

01
Verified trust and transparency
Cal.com’s SOC 2 Type II certification is audited by an independent third party, proving our controls work as intended, meaning you can trust that your data is handled securely and consistently.
02
Enterprise-grade data protection
Every booking and message is encrypted, access-controlled, and monitored, meaning your information stays private and protected from unauthorized access.
03
Procurement-ready compliance
For enterprises, SOC 2 is often required. Cal.com provides documentation and audit reports to simplify your vendor approval, meaning faster, compliant onboarding for your team.
03
Continuous monitoring and independent audits
We use Vanta to monitor compliance year-round, while an external auditor verifies our controls annually, meaning your data stays secure through continuous oversight and verified assurance.
01
Domain-wide delegation
Simplify setup and ensure SOC 2 compliance across your organization. Cal.com gives admins centralized control over scheduling, bookings, and access.

02
SAML SSO, SCIM provisioning
SAML SSO, SCIM provisioning, and automated workflows provide admins with full visibility and control, ensuring SOC 2 access requirements are met.

03
Privacy compliance tools
RBAC, SAML SSO, and configurable data residency options simplify privacy management, ensuring SOC 2 and regulatory compliance across your organization.

03
Encryption and security monitoring
Cal.com encrypts scheduling data in transit and at rest, with ongoing monitoring and vulnerability management to meet SOC 2 security standards.

Healthcare & wellness
Manage patient scheduling, telehealth sessions, and client intakes with SOC 2-compliant security and continuous monitoring to protect sensitive data.
Government & finance
SOC 2-compliant scheduling built with enterprise-grade security features to safeguard sensitive data and meet strict regulatory standards.
Sales & GTM teams
Route demo requests, coordinate CSM calls, and manage onboarding with SOC 2-certified infrastructure, ensuring privacy and security for all interactions.
Compliance and security beyond SOC Type II
Your scheduling system shouldn’t be the weakest link in your compliance stack. SOC 2 certification is part of Cal.com’s broader commitment to privacy and data protection. With our privacy-by-design architecture, you gain the confidence of HIPAA, SOC 2 Type II, ISO 27001, CCPA, and GDPR compliance, all without sacrificing usability. Learn more about Cal.com's compliance below!






Is Cal.com SOC 2 certified?
Yes. Cal.com is SOC 2 Type II certified, meaning our security, availability, and confidentiality controls have been audited and verified by an independent third party.
What is the difference between SOC 2 Type I and Type II?
Type I reviews whether security controls are designed effectively at one point in time. Type II evaluates whether those controls are followed and effective over several months, meaning Cal.com’s certification proves ongoing, consistent compliance.
How often is Cal.com audited?
Cal.com undergoes an independent external audit every year to maintain our SOC 2 Type II certification. Between audits, we use Vanta to continuously monitor our internal controls and ensure compliance every day.
Can I request a copy of Cal.com’s SOC 2 report?
Yes. Enterprise customers and partners can request access to our most recent SOC 2 report. Contact our team for details by sending an email to [email protected] or by scheduling a demo.
How does SOC 2 compliance protect my organization?
SOC 2 compliance ensures that Cal.com maintains strict standards for security, availability, and confidentiality, meaning your organization’s data is encrypted, access-controlled, and continuously monitored to reduce risk.
Does Cal.com meet other compliance standards?
Yes. In addition to SOC 2 Type II, Cal.com complies with HIPAA, ISO/IEC 27001, GDPR, and CCPA. Together, these frameworks provide a complete security foundation for organizations of all sizes.
Choose Cal.com for verified, SOC 2 compliant scheduling
Cal.com’s SOC 2 certification, independent audits, and continuous monitoring with Vanta ensure your data is always protected. Choose a platform built for trust, compliance, and enterprise-grade security.














