Security & Trust Center
Security practices built around accountability, resilience, and trust.
This Trust Center explains the principles Culligan Technology uses to protect customer environments, manage access, reduce operational risk, support resilience, and handle security concerns. Specific controls and responsibilities depend on the selected service, customer configuration, and governing agreement.
Our Trust Commitments
Principles that guide how customer technology is managed.
Trust depends on more than individual security tools. It requires governance, clear ownership, controlled access, operational discipline, transparency, and preparation for disruption.
Security by design
Security is considered during architecture, deployment, configuration, administration, monitoring, support, backup, recovery, and service improvement.
Controlled access
Administrative privileges are restricted to authorized personnel and aligned with role, responsibility, customer authorization, and operational need.
Operational accountability
Responsibilities, escalation paths, service scope, support expectations, and material changes should remain documented and understandable.
Clear communication
Customers should receive practical information about material service concerns, security risk, decisions, responsibilities, and recommended next steps.
Data stewardship
Customer information is handled according to service requirements, approved access, contractual obligations, applicable controls, and customer direction.
Resilience planning
Backup, recovery, continuity, incident coordination, and restoration planning are addressed according to the systems and services included.
Security Control Areas
Layered protection across people, systems, data, and operations.
The controls applied to a specific customer environment depend on the selected service, management level, technical compatibility, customer policy, and assigned responsibilities.
Identity and access management
Controls intended to reduce unauthorized access and excessive administrative privilege.
- Role-based access and least privilege
- Multifactor authentication where supported and required
- Controlled administrator accounts
- Access review, modification, and removal processes
- Customer authorization for material access changes
Endpoint and server security
Management and protection practices for covered workstations, servers, and supported workloads.
- Monitoring, maintenance, and security oversight
- Endpoint protection and threat detection options
- Patch and vulnerability remediation coordination
- Configuration and policy management
- Investigation and response according to service scope
Network and cloud security
Security oversight for supported connectivity, cloud workloads, identities, and configurations.
- Firewall and network configuration oversight
- Secure remote connectivity options
- Cloud identity and access controls
- Configuration, availability, and security monitoring
- Segmentation and exposure reduction where appropriate
Data protection and recovery
Controls designed to reduce data loss and support restoration of covered systems and information.
- Encryption in transit and at rest where supported
- Backup scheduling and monitoring options
- Retention aligned with service requirements
- File-level and system recovery options
- Recovery planning and validation according to scope
Monitoring and logging
Operational and security visibility across covered systems, services, and support activity.
- System health and availability monitoring
- Security event collection and review options
- Remote support and administrative activity logging
- Alert investigation and escalation procedures
- Reporting appropriate to the management level
Governance and third-party risk
Processes intended to keep service responsibilities, risk, and external dependencies understood.
- Defined service scope and customer responsibilities
- Third-party service review appropriate to risk
- Security and operational change coordination
- Incident escalation and communication paths
- Documentation and policy support according to scope
Operational Resilience
Preparation for disruption is part of responsible technology management.
Resilience requires more than having a backup. It requires understanding important systems, recovery priorities, dependencies, retention, restoration methods, escalation paths, and the responsibilities of everyone involved.
- Backup monitoring and exception review
- File and full-system recovery options
- Recovery objective planning
- Continuity and failover considerations
- Restoration procedures and validation
- Incident escalation and coordination
- Configuration and documentation support
- Post-incident improvement planning
Data & Privacy
Customer information remains the customer’s information.
Culligan Technology does not claim ownership of customer data or intellectual property managed through a service relationship. Access to customer information is limited to authorized business and service purposes.
Data location, retention, deletion, portability, encryption, and third-party processing can vary by service and provider. These requirements should be documented during service design and in the governing agreement when they are material to the customer.
Security Coverage
Core, Advanced, and Assured management.
Security oversight and operational responsibility increase across the three management levels. Exact inclusions are documented in the applicable proposal, service agreement, and statement of work.
Not every control or response action is included with every level. Customer systems, compatibility, requirements, and assigned responsibilities also affect final coverage.
Management Level
Core
Essential proactive management and baseline protection for a reliable technology foundation.
- Routine monitoring and maintenance
- Baseline endpoint and access security
- Patch and configuration management
- Standard support and escalation
- Service and asset visibility
Management Level
Advanced
Expanded management and stronger security oversight for organizations with greater complexity or risk.
- Enhanced endpoint and identity security
- Vulnerability and remediation coordination
- Expanded monitoring and investigation
- Security event response and escalation
- Regular risk and service reporting
Management Level
Assured
Comprehensive technology and security management for the highest level of operational assurance.
- Comprehensive managed operations
- Assured monitoring and security response
- Incident and continuity coordination
- Governance and compliance support
- Strategic risk reduction and improvement
Security Review Requests
Additional assurance information may be available for qualified requests.
Prospective and existing customers may request further information when it is reasonably necessary for vendor review, procurement, insurance, risk management, or compliance evaluation.
Information that may be reviewed
Availability depends on relevance, confidentiality, customer status, and the purpose of the request.
- Security questionnaires and control summaries
- Business continuity and incident-response summaries
- Cyber insurance verification, when applicable
- Data-processing and service-provider information
- Architecture or data-flow discussions at an appropriate level
How requests are handled
Sensitive information is not posted publicly and may require review, customer qualification, a legitimate business need, and an appropriate confidentiality agreement.
- Requests are reviewed for relevance and sensitivity
- Confidential information may require an NDA
- Internal security details may be limited or withheld
- Customer and third-party confidential information is not disclosed
- Contractual documents govern actual obligations
Responsible Disclosure
Report a suspected security issue responsibly.
Security researchers, customers, and members of the public may report a suspected vulnerability affecting a Culligan Technology-managed public service or website. Reports should contain enough information to understand and reproduce the issue without exposing customer information.
Do not access, modify, download, retain, or disclose customer data; disrupt services; use automated high-volume testing; perform social engineering; or continue testing after confirming a vulnerability.
Trust Center FAQ
Common questions about security, data, access, and assurance.
These answers provide general public information. The applicable agreement controls when a customer’s contracted service differs from this overview.
Who owns customer data?
The customer retains ownership of its data and intellectual property. Culligan Technology does not claim ownership of customer information managed through the service relationship.
Where is customer data stored?
U.S.-based data residency is preferred for standard services where supported. Actual storage and processing locations depend on the selected service, customer configuration, third-party provider, and contractual requirements.
Does Culligan Technology use multifactor authentication?
Multifactor authentication is used and recommended where supported and appropriate to the system, account, risk, customer requirement, and service responsibility. Exact coverage can vary by service and customer environment.
Is remote administrative activity controlled and logged?
Remote support and administration use approved management processes. Activity logging, authorization, retention, and available audit detail depend on the management platform, selected service, system capability, and customer agreement.
Do all customers receive 24/7 security monitoring?
No. Qualifying managed service coverage may include 24/7 remote security operations. Monitoring, investigation, containment, escalation, and response activities are defined by the selected management level and service agreement.
Does this page certify compliance with a particular framework?
No. This page describes general security and trust practices. It does not represent a certification, independent audit opinion, legal guarantee, or claim of compliance with a specific framework unless a separate written document expressly states otherwise.
Can customers receive a security questionnaire or supporting documentation?
Qualified prospective and existing customers may request additional information. Disclosure depends on relevance, confidentiality, legitimate business need, and whether an appropriate nondisclosure agreement is required.
How are security incidents communicated?
Investigation, escalation, customer notification, coordination, and response depend on the affected service, available information, assigned responsibilities, severity, and the applicable agreement. Existing clients should follow their established escalation process.
This Trust Center is provided for general informational purposes and does not amend any contract, create a warranty, or replace a customer agreement, statement of work, privacy notice, data-processing agreement, or legal obligation.
Need security information for a vendor or risk review?
Send the purpose of the request, the organization involved, the information needed, the due date, and whether a confidentiality agreement is available.