Security & data protection

Everything on this page is already binding — it is the buyer-facing summary of commitments written into our Data Processing Agreement and Service Level Agreement. Nothing here is a new promise; it is the same text, in the order a buyer actually asks about it.

安全与数据保护

这一页上的每一条都已经具有约束力 —— 它是数据处理协议服务等级协议里既有条款的采购视角摘要。这里没有任何新承诺,只是把同样的内容,按买家真正会问的顺序重排了一遍。

Seguridad y protección de datos

Todo lo que aparece aquí ya es vinculante — es el resumen, en lenguaje de comprador, de los compromisos escritos en nuestro Acuerdo de Tratamiento de Datos y nuestro Acuerdo de Nivel de Servicio. No hay ninguna promesa nueva: es el mismo texto, en el orden en que un comprador realmente pregunta.

Last reviewed: August 9, 2026 · Caliradi LLC, a DSYP Group company最近复核:2026 年 8 月 9 日 · Caliradi LLC(DSYP Group 成员公司)Última revisión: 9 de agosto de 2026 · Caliradi LLC, empresa del grupo DSYP

1. Technical & organizational measures1. 技术与组织措施1. Medidas técnicas y organizativas

2. What you can verify yourself, right now2. 你现在就能自己验证的部分2. Lo que puedes verificar tú mismo, ahora

Security claims are easy to write and hard to check. These ones you can check in thirty seconds — open your browser's developer tools on any page of this site, or run curl -I https://caliradi.ai/, and read the response headers:

安全声明写起来容易、核起来难。下面这些三十秒就能自己核实 —— 在本站任意页面打开浏览器开发者工具,或者执行 curl -I https://caliradi.ai/,直接读响应头:

Las afirmaciones de seguridad son fáciles de escribir y difíciles de comprobar. Estas se comprueban en treinta segundos: abre las herramientas de desarrollo en cualquier página de este sitio, o ejecuta curl -I https://caliradi.ai/, y lee las cabeceras de respuesta:

Header响应头Cabecera What it means for you对你意味着什么Qué significa para ti
strict-transport-security One year, including subdomains. Browsers refuse to talk to us over plain HTTP at all.一年期、含子域。浏览器根本不会以明文 HTTP 与我们通信。Un año, incluidos subdominios. El navegador ni siquiera intenta HTTP sin cifrar.
content-security-policy Scripts are allowed only from this origin or by exact hash — there is no unsafe-inline. Injected script does not execute.脚本只允许来自本站或按精确哈希放行 —— 没有 unsafe-inline。被注入的脚本不会执行。Los scripts solo se permiten desde este origen o por hash exacto — sin unsafe-inline. Un script inyectado no se ejecuta.
x-content-type-options nosniff — the browser will not re-interpret an upload as executable content.nosniff —— 浏览器不会把上传的文件重新猜成可执行内容。nosniff — el navegador no reinterpreta una subida como contenido ejecutable.
x-frame-options The site cannot be silently framed inside someone else's page (clickjacking).本站无法被别人的页面静默套框(点击劫持)。El sitio no puede incrustarse en la página de otro (clickjacking).
referrer-policy strict-origin-when-cross-origin — outbound links leak the domain, never the full path.strict-origin-when-cross-origin —— 外链只带出域名,绝不带完整路径。strict-origin-when-cross-origin — los enlaces salientes filtran el dominio, nunca la ruta completa.
permissions-policy Camera, microphone and geolocation are switched off for this site at the browser level.摄像头、麦克风、定位在浏览器层面对本站直接关闭。Cámara, micrófono y geolocalización están desactivados a nivel de navegador.

3. Your data stays yours3. 你的数据始终属于你3. Tus datos siguen siendo tuyos

4. Sub-processors & cross-border transfers4. 子处理方与跨境传输4. Subencargados y transferencias internacionales

The full list — hosting and CDN, AI inference, the customer-record platform, Stripe for payments, Cloudflare for network security and DNS, and transactional email — is published in Section 7 of the DPA, with the location of each.

完整清单 —— 托管与 CDN、AI 推理、客户档案平台、支付所用的 Stripe、承担网络安全与 DNS 的 Cloudflare、事务性邮件 —— 连同各自所在地,公布在数据处理协议第 7 节

La lista completa — alojamiento y CDN, inferencia de IA, la plataforma de registros de clientes, Stripe para pagos, Cloudflare para seguridad de red y DNS, y correo transaccional — se publica con su ubicación en la Sección 7 del DPA.

5. Incidents & availability5. 事故与可用性5. Incidentes y disponibilidad

6. Privacy by default on this website6. 本网站默认保护隐私6. Privacidad por defecto en este sitio

Our analytics are cookie-less: no cookies are set, no IP address is stored, and there is no cross-site tracking. If your browser sends a Global Privacy Control signal, we do not load analytics at all — that is enforced in code, not in a policy document. Details are in Privacy and Cookies. Compliance is built to GDPR, CCPA and PIPL.

我们的统计不使用 cookie:不种 cookie、不存 IP、不做跨站追踪。若你的浏览器发出 Global Privacy Control 信号,我们直接不加载统计脚本 —— 这一条由代码兑现,不是政策文件里的一句话。细节见隐私政策Cookie 说明。合规按 GDPR、CCPA、PIPL 构建。

Nuestra analítica no usa cookies: no se instalan cookies, no se almacena la IP y no hay seguimiento entre sitios. Si tu navegador envía la señal Global Privacy Control, directamente no cargamos analítica — está implementado en el código, no solo en una política. Detalles en Privacidad y Cookies. Cumplimiento conforme a GDPR, CCPA y PIPL.

7. Reporting a security issue7. 报告安全问题7. Reportar un problema de seguridad

Email [email protected] with the subject "Security"发邮件至 [email protected],主题写「Security」Escribe a [email protected] con el asunto "Security"
Include what you found and how to reproduce it. Please give us a reasonable window to fix an issue before disclosing it publicly. Existing customers can also request a counter-signed DPA, our sub-processor list, or an annual audit under Section 8 of the DPA at the same address.请说明你发现了什么、如何复现。公开披露前请留给我们合理的修复窗口。现有客户也可通过同一邮箱申请对签版数据处理协议、子处理方清单,或依据协议第 8 节行使年度审计权。Indica qué encontraste y cómo reproducirlo. Danos un plazo razonable para corregirlo antes de divulgarlo públicamente. Los clientes actuales también pueden solicitar en la misma dirección un DPA contrafirmado, la lista de subencargados o la auditoría anual conforme a la Sección 8 del DPA.