Security & Trust Center

Security practices built around accountability, resilience, and trust.

This Trust Center explains the principles Culligan Technology uses to protect customer environments, manage access, reduce operational risk, support resilience, and handle security concerns. Specific controls and responsibilities depend on the selected service, customer configuration, and governing agreement.

Customer data ownership Role-based access Security-first operations
Customer ownership Customers retain ownership of their data and intellectual property.
Least-privilege access Administrative access is limited according to role and business need.
Controlled operations Remote administration and support activity use approved management processes.
Defined responsibility Actual obligations and service scope are documented in customer agreements.

Our Trust Commitments

Principles that guide how customer technology is managed.

Trust depends on more than individual security tools. It requires governance, clear ownership, controlled access, operational discipline, transparency, and preparation for disruption.

Security by design

Security is considered during architecture, deployment, configuration, administration, monitoring, support, backup, recovery, and service improvement.

Controlled access

Administrative privileges are restricted to authorized personnel and aligned with role, responsibility, customer authorization, and operational need.

Operational accountability

Responsibilities, escalation paths, service scope, support expectations, and material changes should remain documented and understandable.

Clear communication

Customers should receive practical information about material service concerns, security risk, decisions, responsibilities, and recommended next steps.

Data stewardship

Customer information is handled according to service requirements, approved access, contractual obligations, applicable controls, and customer direction.

Resilience planning

Backup, recovery, continuity, incident coordination, and restoration planning are addressed according to the systems and services included.

Security Control Areas

Layered protection across people, systems, data, and operations.

The controls applied to a specific customer environment depend on the selected service, management level, technical compatibility, customer policy, and assigned responsibilities.

Identity and access management

Controls intended to reduce unauthorized access and excessive administrative privilege.

  • Role-based access and least privilege
  • Multifactor authentication where supported and required
  • Controlled administrator accounts
  • Access review, modification, and removal processes
  • Customer authorization for material access changes

Endpoint and server security

Management and protection practices for covered workstations, servers, and supported workloads.

  • Monitoring, maintenance, and security oversight
  • Endpoint protection and threat detection options
  • Patch and vulnerability remediation coordination
  • Configuration and policy management
  • Investigation and response according to service scope

Network and cloud security

Security oversight for supported connectivity, cloud workloads, identities, and configurations.

  • Firewall and network configuration oversight
  • Secure remote connectivity options
  • Cloud identity and access controls
  • Configuration, availability, and security monitoring
  • Segmentation and exposure reduction where appropriate

Data protection and recovery

Controls designed to reduce data loss and support restoration of covered systems and information.

  • Encryption in transit and at rest where supported
  • Backup scheduling and monitoring options
  • Retention aligned with service requirements
  • File-level and system recovery options
  • Recovery planning and validation according to scope

Monitoring and logging

Operational and security visibility across covered systems, services, and support activity.

  • System health and availability monitoring
  • Security event collection and review options
  • Remote support and administrative activity logging
  • Alert investigation and escalation procedures
  • Reporting appropriate to the management level

Governance and third-party risk

Processes intended to keep service responsibilities, risk, and external dependencies understood.

  • Defined service scope and customer responsibilities
  • Third-party service review appropriate to risk
  • Security and operational change coordination
  • Incident escalation and communication paths
  • Documentation and policy support according to scope

Operational Resilience

Preparation for disruption is part of responsible technology management.

Resilience requires more than having a backup. It requires understanding important systems, recovery priorities, dependencies, retention, restoration methods, escalation paths, and the responsibilities of everyone involved.

  • Backup monitoring and exception review
  • File and full-system recovery options
  • Recovery objective planning
  • Continuity and failover considerations
  • Restoration procedures and validation
  • Incident escalation and coordination
  • Configuration and documentation support
  • Post-incident improvement planning

Data & Privacy

Customer information remains the customer’s information.

Culligan Technology does not claim ownership of customer data or intellectual property managed through a service relationship. Access to customer information is limited to authorized business and service purposes.

Data location, retention, deletion, portability, encryption, and third-party processing can vary by service and provider. These requirements should be documented during service design and in the governing agreement when they are material to the customer.

Security Coverage

Core, Advanced, and Assured management.

Security oversight and operational responsibility increase across the three management levels. Exact inclusions are documented in the applicable proposal, service agreement, and statement of work.

Not every control or response action is included with every level. Customer systems, compatibility, requirements, and assigned responsibilities also affect final coverage.

Management Level

Core

Essential proactive management and baseline protection for a reliable technology foundation.

  • Routine monitoring and maintenance
  • Baseline endpoint and access security
  • Patch and configuration management
  • Standard support and escalation
  • Service and asset visibility

Management Level

Assured

Comprehensive technology and security management for the highest level of operational assurance.

  • Comprehensive managed operations
  • Assured monitoring and security response
  • Incident and continuity coordination
  • Governance and compliance support
  • Strategic risk reduction and improvement

Security Review Requests

Additional assurance information may be available for qualified requests.

Prospective and existing customers may request further information when it is reasonably necessary for vendor review, procurement, insurance, risk management, or compliance evaluation.

Information that may be reviewed

Availability depends on relevance, confidentiality, customer status, and the purpose of the request.

  • Security questionnaires and control summaries
  • Business continuity and incident-response summaries
  • Cyber insurance verification, when applicable
  • Data-processing and service-provider information
  • Architecture or data-flow discussions at an appropriate level

How requests are handled

Sensitive information is not posted publicly and may require review, customer qualification, a legitimate business need, and an appropriate confidentiality agreement.

  • Requests are reviewed for relevance and sensitivity
  • Confidential information may require an NDA
  • Internal security details may be limited or withheld
  • Customer and third-party confidential information is not disclosed
  • Contractual documents govern actual obligations
Submit a security review request

Responsible Disclosure

Report a suspected security issue responsibly.

Security researchers, customers, and members of the public may report a suspected vulnerability affecting a Culligan Technology-managed public service or website. Reports should contain enough information to understand and reproduce the issue without exposing customer information.

Do not access, modify, download, retain, or disclose customer data; disrupt services; use automated high-volume testing; perform social engineering; or continue testing after confirming a vulnerability.

Trust Center FAQ

Common questions about security, data, access, and assurance.

These answers provide general public information. The applicable agreement controls when a customer’s contracted service differs from this overview.

Who owns customer data?

The customer retains ownership of its data and intellectual property. Culligan Technology does not claim ownership of customer information managed through the service relationship.

Where is customer data stored?

U.S.-based data residency is preferred for standard services where supported. Actual storage and processing locations depend on the selected service, customer configuration, third-party provider, and contractual requirements.

Does Culligan Technology use multifactor authentication?

Multifactor authentication is used and recommended where supported and appropriate to the system, account, risk, customer requirement, and service responsibility. Exact coverage can vary by service and customer environment.

Is remote administrative activity controlled and logged?

Remote support and administration use approved management processes. Activity logging, authorization, retention, and available audit detail depend on the management platform, selected service, system capability, and customer agreement.

Do all customers receive 24/7 security monitoring?

No. Qualifying managed service coverage may include 24/7 remote security operations. Monitoring, investigation, containment, escalation, and response activities are defined by the selected management level and service agreement.

Does this page certify compliance with a particular framework?

No. This page describes general security and trust practices. It does not represent a certification, independent audit opinion, legal guarantee, or claim of compliance with a specific framework unless a separate written document expressly states otherwise.

Can customers receive a security questionnaire or supporting documentation?

Qualified prospective and existing customers may request additional information. Disclosure depends on relevance, confidentiality, legitimate business need, and whether an appropriate nondisclosure agreement is required.

How are security incidents communicated?

Investigation, escalation, customer notification, coordination, and response depend on the affected service, available information, assigned responsibilities, severity, and the applicable agreement. Existing clients should follow their established escalation process.

Important notice

This Trust Center is provided for general informational purposes and does not amend any contract, create a warranty, or replace a customer agreement, statement of work, privacy notice, data-processing agreement, or legal obligation.

Need security information for a vendor or risk review?

Send the purpose of the request, the organization involved, the information needed, the due date, and whether a confidentiality agreement is available.

Submit a Trust Request