Security researchers schedule calls with clients whose networks are being tested. The metadata that Client X has a pentest underway is extremely sensitive — it can be signal intelligence for a motivated attacker.
Why security researchers and penetration testers need scheduling privacy specifically
Security Researchers And Penetration Testers handle data with distinct confidentiality expectations — client network exposure. Client trust in the profession is built on absolute discretion, and every data leak (even metadata) chips away at that trust.
What to set up
Share booking links only in encrypted channels. Disable any public directory. Ensure your scheduling tool has ongoing security audits and responsible disclosure procedures.
The Cal Clear configuration
A Cal Clear booking link for high-privacy professions: use the Pro plan for private (non-indexed) links, enable email verification to block impersonators, set auto-delete to 30 days, disable any public directory listing, and use reCAPTCHA on public-facing links.
This is part of our privacy-first scheduling pillar guide — 18 articles covering every privacy angle.
Frequently Asked Questions
Is a standard scheduling tool safe for security researchers and penetration testers?
Tools like Calendly and Acuity load third-party analytics on booking pages, which leaks metadata about who your clients are. For security researchers and penetration testers with strict confidentiality obligations, a privacy-first tool is meaningfully better.
Does Cal Clear sign a BAA / DPA for security researchers and penetration testers?
Cal Clear signs standard DPAs with all business customers. HIPAA BAAs are available for enterprise healthcare customers — contact support to discuss.
Try privacy-first scheduling, free
Cal Clear runs zero trackers on booking pages and auto-deletes booking data on your schedule. Start at calclear.app.