How we protect the data you share with us.
In one page.
Everything an enterprise procurement, security, or compliance team needs to evaluate CORE — concentrated in a single page instead of scattered across five PDFs.
Zero Retention — the single most important thing to know
Nothing you share with CORE — your business requirements, uploaded documents, existing code, or the software CORE generates — is ever used to train, fine-tune, or improve any AI model. Ever.
Your data stays inside your project's boundary. Access is limited to systems that directly serve your build. When your engagement ends, your data is deleted according to a documented retention schedule. What CORE builds for you is yours alone — permanently.
Security built into every layer
CORE's security posture is defence-in-depth, not perimeter-only. Each layer has its own controls, monitored independently.
- TLS 1.3 for data in transit (TLS 1.2 minimum for legacy clients)
- AES-256 for data at rest
- Envelope encryption with regular key rotation
- Secrets managed via dedicated secret management systems (never in code, config, or logs)
- SAML 2.0 / OIDC single sign-on (Okta, Azure AD, Google Workspace)
- Multi-factor authentication enforced for administrative access
- Role-based access controls with segregation of duties
- All administrative actions logged with immutable audit trails
- Append-only audit logs across data-affecting operations
- Configurable retention (typical: 7 years for SOX-scope data)
- Log integrity monitoring against tampering
- Access logs available for customer-side review
- Input validation and output encoding
- SQL-injection, XSS, and CSRF mitigations built in
- Rate limiting and abuse prevention
- Prompt injection defence at AI layer
- Deployed on major cloud providers (AWS, Azure, GCP) at customer choice
- Configurable data residency (US, EU, UK, APAC)
- Cloudflare edge protection (bot mitigation, DDoS)
- Automated backups with tested restoration
- 24-hour customer notification for confirmed security incidents affecting them
- Documented containment, eradication, and recovery playbooks
- Post-incident review and customer-facing report
- Responsible disclosure programme via report@ssdbtech.com
Compliance frameworks CORE aligns with
CORE's controls are designed to satisfy — or generate applications that satisfy — the requirements of the following frameworks. Formal certifications are progressing; "aligned" means our design and controls meet the framework's requirements, "certified" indicates completed third-party audit.
TYPE II
27001
800-53
DPDP
DSS
Responsible disclosure
Security researchers and customers who identify a potential vulnerability can report it confidentially to report@ssdbtech.com. We respond within 48 hours and follow a documented triage and remediation process.
Detailed policy documents: Security Policy · Privacy Policy · Acceptable Use Policy
Need something specific for your evaluation?
Compliance questionnaire, DPA request, penetration test report, subprocessor list — we're set up to respond.
Request security documentation →