Security

Built for transactional messaging and operational trust.

Aculio is designed around the realities of SMS compliance, Acuity booking-event limits, and small-business scheduling operations.

Credential handling

Payment, messaging, and calendar connection secrets are handled server-side and are never exposed to the browser.

SMS consent

Waitlist joins capture transactional SMS consent timestamps and customer-facing opt-in language.

Event routing

Aculio centralizes booking events so businesses do not need a separate integration for every workflow.

Billing security

Payment collection is handled by a secure payment processor. Aculio stores subscription status, not payment card data.

Data Transit & Protection Standards

A detailed breakdown of how Aculio secures your customer databases, API secrets, and webhook event payloads.

1. Encryption in Transit

All client and admin traffic to the Aculio dashboard is expected to run over HTTPS in production, and workspace sessions are kept in HTTP-only cookies rather than browser-readable local storage.

2. API & OAuth Token Security

Calendar authorization secrets and Twilio API credentials are encrypted at rest using AES-256-GCM. Decryption occurs strictly server-side inside secure environment runtimes.

3. Signed Webhook Integrity

Billing and Acuity webhook processing are designed to require signature validation when their production secrets are configured, preventing unauthorized event replay from mutating workspace state.

4. HIPAA Alignment

Strict tenant data isolation and transactional logging keep Aculio compliant for healthcare clinics, sports studios, and high-volume wellness operations.