Cara & Bao — Operating systems that drive business

Security

Security is a way of building — not a badge wall.

This page explains Cara & Bao’s security philosophy. It does not claim certifications we have not earned, and it does not invent controls that are not yet established.

Last updated: 2026-07-19

Security by design

Security belongs in architecture, defaults and review habits — not as a layer applied after shipping.

We prefer understandable systems. Clarity makes risk visible; unnecessary complexity hides it.

Least complexity

Fewer moving parts mean fewer places for failure or abuse to hide.

We aim to collect and retain only what operations require.

Responsible engineering

Changes should be reviewable, releases predictable, and operational impact considered before novelty.

We treat security work as part of ordinary engineering quality — alongside reliability and accessibility.

Access control philosophy

Access should map to real roles and obligations.

Privileges should be intentional, reviewable and removable when no longer needed.

Operational transparency

We prefer documentation that matches reality. If a control is not yet established, we will not describe it as if it were.

Responsible disclosure

If you believe you have found a vulnerability in a system operated by Cara & Bao, please report it privately so we can investigate.

Email: info@carabao.digital with a clear subject line such as “Security disclosure”.

Please include enough detail to reproduce the issue, and allow a reasonable time for assessment and remediation coordination before public discussion.

We do not currently operate a public bug bounty programme. We appreciate good-faith reports and will respond as promptly as we can.

  • Scope is limited to systems operated by Cara & Bao.
  • Do not perform denial-of-service or availability-degrading testing.
  • Do not use social engineering against people.
  • Do not access, modify, exfiltrate or destroy third-party or customer data.
  • Do not publicly disclose a vulnerability before reasonable remediation coordination.

Incident handling philosophy

If a security incident affects people who entrusted us with information, we aim to investigate carefully, contain impact, and communicate with clarity to those who need to know.

Specific notification timelines for paid customer environments will be defined in future customer agreements where required.

Future certifications

We may pursue formal certifications or attestations as the company and products mature.

Until those exist, we will not imply SOC 2, ISO 27001, HIPAA, GDPR certification, or similar. Principles come first; badges come later — if earned.