Trust & Security · Columa

Security your business can count on.

Columa answers your calls, books your jobs, and captures your leads. That means your data — and your customers' — is in our care. We treat protecting it as core to the product, not an afterthought.

TLS 1.2+
Encrypted end to end
PCI Level 1
Payments via Stripe
Always on
Cloudflare protection
Reviewed
Ongoing security audits

How we protect you · 01

The safeguards behind every conversation.

Encrypted everywhere

Every connection to Columa is protected with modern TLS, with a TLS 1.2 minimum enforced at the edge — legacy protocols are refused outright. HTTP Strict Transport Security (HSTS) tells browsers to connect securely from the very first request. Data moving between your customers, your site, and Columa is never sent in the clear.

Payments handled by Stripe

Card payments run through Stripe, a PCI-DSS Level 1 provider — the highest tier. Columa never sees or stores your full card number.

Global edge protection

Columa runs behind Cloudflare's network, which absorbs denial-of-service attacks and filters automated bots before they ever reach the service.

Least-privilege access

Access to features and data is scoped and verified on our servers, so every account reaches only what it is entitled to — never more.

Keys that never leave us

Connections to third-party tools use industry-standard OAuth, and sensitive access keys — including the AI keys that power Olive — stay encrypted on Columa's servers, never on your site or in a browser.

Spam & abuse filtering

Public forms and the chat assistant are guarded with bot detection and rate limiting, so junk traffic is turned away and your real leads come through clean.

Staying ahead · 02

Security is a habit, not a checkbox.

We regularly review our own code and infrastructure — including adversarial testing of our public endpoints — and fix what we find. Software is never "done," so neither is this work. Recent hardening includes enforcing a TLS 1.2 protocol floor and strict transport security (HSTS) across Columa domains.

Responsible disclosure

Found something? We want to hear from you.

If you believe you've discovered a security issue in Columa, please tell us before disclosing it publicly. We investigate every good-faith report and will keep you updated on our progress.

  • Share enough detail for us to reproduce the issue.
  • Give us a reasonable window to investigate and fix before going public.
  • Don't access, modify, or delete data that isn't yours while testing.
Report a vulnerability
security@columa.ai

We aim to acknowledge good-faith reports promptly. Please include steps to reproduce and your contact details.

Last reviewed · July 2026

Trust, built in

Peace of mind, on every call.

Columa is built and backed by a team that runs real businesses — so we hold your data to the standard we'd want for our own. Questions about our security or privacy practices? We're glad to answer.

An Olive Group product