FORCE-enabled row-level security. A query that never sets the tenant context returns nothing. Cross-tenant isolation is a test in CI, not a convention.
SOC 2 CC6.1 · HIPAA §164.312(a)(1)
For security teams, procurement reviewers, and budget-holders: the scope of the technical controls, the boundary between what Caisson ships and what remains yours, who you're buying from and how invoicing works, and how to request documentation.
Caisson ships the technical controls. The audit remains yours.
Caisson is a codebase. It implements the technical requirements SOC 2 and HIPAA demand: fail-closed access control, tamper-evident logging, WORM storage, and encrypted field storage. It generates evidence artifacts you hand to an auditor. It does not replace the auditor, the audit engagement, or the organizational controls (HR, vendor management, incident response) the frameworks also require. Caisson is not itself SOC 2 or HIPAA certified, and never claims to be.
FORCE-enabled row-level security. A query that never sets the tenant context returns nothing. Cross-tenant isolation is a test in CI, not a convention.
SOC 2 CC6.1 · HIPAA §164.312(a)(1)
Evidence buckets default to GOVERNANCE-mode Object Lock: objects can't be overwritten or deleted inside the retention window by an ordinary caller. Escalating a bucket to COMPLIANCE mode (where the lock holds against any caller, including an operator with a leaked root key) is an explicit, irreversible, production-gated opt-in, never the silent default.
SOC 2 CC7.2 · HIPAA §164.312(c)(1)
Every privileged action hashes into a chain. Tampering with any historical row breaks every link after it: the break is detectable, provable, and exportable to an auditor.
SOC 2 CC7.2 · HIPAA §164.312(b)
AES-256-GCM authenticated encryption at the column level. Each tenant's key material is scoped to their row context. No plaintext key material in the application layer.
HIPAA §164.312(a)(2)(iv)
Caisson is licensed to you by Caisson Software LLC, based in Atlanta, Georgia. That’s the party behind the software: it owns the source, grants the license, and stands behind it under the Commercial License Agreement (the EULA). See the EULA for the entity’s full legal description.
Your checkout is handled by a separate party. See the next section. Two different roles, both named on your paperwork: Caisson licenses the software, Paddle sells and bills the transaction.
Every order runs through Paddle.com, Caisson’s merchant of record. Paddle collects payment, calculates and remits sales tax and VAT for your jurisdiction, and issues your order receipt: that receipt is your invoice for the purchase. Which Paddle entity is the seller of record for your specific order is stated in Paddle’s own buyer terms, presented to you at checkout.
The perpetual license fee is a one-time charge per bundle or module and includes 12 months of updates from your Order date, renewable afterward at 40% of the then-current list price per year. A Compliance Updates subscription, where purchased, bills on a recurring basis until cancelled and delivers new package versions with updated control mappings; neither is required, and skipping either doesn’t affect the perpetual license for versions you already have. The license itself doesn’t expire, doesn’t require renewal, and doesn’t call home to stay valid.
Refunds: every purchase comes with an unconditional 14-day money-back guarantee. Request a refund within 14 days for any reason and you get a full refund, whether or not you’ve downloaded or used the software, and regardless of location or consumer/business status. Paddle, as merchant of record, returns the payment to your original method. An approved refund revokes the entitlement it granted and returns unused credits; access and credits already used aren’t clawed back. If one order covered more than one bundle or module, tell us which line item you’re refunding: they’re refundable individually.
We respond to documented requests from security reviewers and procurement teams within 5 business days.
Architecture & data-flow
System architecture diagram, data-flow documentation, and infrastructure topology. Available on request.
Control mapping
A mapping of Caisson modules to SOC 2 TSC and HIPAA §164.3xx control clauses. Downloadable in CSV and PDF.
W-9 and entity documents
Email [email protected] with your organization name and we'll send a completed W-9 and Caisson Software LLC's entity details for your vendor file.
Vulnerability reporting
Email [email protected] with a description and reproduction steps. We triage every valid report. There is no formal bug-bounty program.
Procurement questionnaires
Send your standard security questionnaire to [email protected]. We respond to documented requests from qualified buyers.
For security documentation, procurement questionnaires, W-9 requests, or to discuss the technical controls in detail, email [email protected] (security/technical) or [email protected] (contracts, tax, entity). Ready to purchase or evaluate? See pricing.