Security and compliance built for enterprise procurement

CORE is designed to SOC 2 controls: SSO/SAML, role-based access, encryption at rest and in transit, audit logs on every action, and no training on customer code by default. Below is the full posture. Documentation available on request under NDA.

Active
Zero Retention Policy
TLS 1.3 · AES-256
Encryption in transit & at rest
SSO / SAML
Enterprise authentication
Built in
SOC 2 controls in every build

Zero Retention — the single most important thing to know

Nothing you share with CORE — your business requirements, uploaded documents, existing code, or the software CORE generates — is ever used to train, fine-tune, or improve any AI model. Ever.

Your data stays inside your project's boundary. Access is limited to systems that directly serve your build. When your engagement ends, your data is deleted according to a documented retention schedule. What CORE builds for you is yours alone — permanently.

Security built into every layer

CORE's security posture is defense-in-depth, not perimeter-only. Each layer has its own controls, monitored independently.

🔐
Encryption
All data encrypted in transit and at rest using industry-standard cryptography.
  • TLS 1.3 for data in transit (TLS 1.2 minimum for legacy clients)
  • AES-256 for data at rest
  • Envelope encryption with regular key rotation
  • Secrets managed via dedicated secret management systems (never in code, config, or logs)
👤
Access & Authentication
Least-privilege access with enterprise SSO integration.
  • SAML 2.0 / OIDC single sign-on (Okta, Azure AD, Google Workspace)
  • Multi-factor authentication enforced for administrative access
  • Role-based access controls with segregation of duties
  • All administrative actions logged with immutable audit trails
📋
Audit & Logging
Complete, immutable audit trails for compliance and forensics.
  • Append-only audit logs across data-affecting operations
  • Configurable retention (typical: 7 years for SOX-scope data)
  • Log integrity monitoring against tampering
  • Access logs available for customer-side review
🛡
Application Security
Applications generated by CORE incorporate OWASP-aligned protections by default.
  • Input validation and output encoding
  • SQL-injection, XSS, and CSRF mitigations built in
  • Rate limiting and abuse prevention
  • Prompt injection defense at AI layer
🌐
Infrastructure
Hosted on enterprise-grade cloud infrastructure with configurable data residency.
  • Deployed on major cloud providers (AWS, Azure, GCP) at customer choice
  • Configurable data residency (US, EU, UK, APAC)
  • Cloudflare edge protection (bot mitigation, DDoS)
  • Automated backups with tested restoration
🚨
Incident Response
Documented incident response with defined SLAs.
  • 24-hour customer notification for confirmed security incidents affecting them
  • Documented containment, eradication, and recovery playbooks
  • Post-incident review and customer-facing report
  • Responsible disclosure program via report@ssdbtech.com

Compliance frameworks CORE aligns with

Every system CORE builds has the relevant controls designed in at blueprint stage rather than retrofitted before an audit — so the software you receive is built to satisfy the frameworks below, with the control mappings and evidence produced alongside it. These are statements about the software CORE builds for you, not claims that SSDB Tech holds third-party certifications of its own — we hold none, and we say so further down this page rather than leaving it to inference.

SOC 2
CONTROLS
SOC 2 controls
Built into every system
ISO
27001
ISO 27001
Controls aligned
NIST
800-53
NIST 800-53
Controls aligned
GDPR
DPDP
GDPR & DPDP
Data protection compliant
HIPAA
HIPAA
Applicable controls built-in
OWASP
OWASP Top 10
Mitigations by default
SOX
SOX (§404)
Audit-trail generation
PCI
DSS
PCI DSS
Applicable controls available

Responsible disclosure

Security researchers and customers who identify a potential vulnerability can report it confidentially to report@ssdbtech.com. We respond within 48 hours and follow a documented triage and remediation process.

Detailed policy documents: Security Policy · Privacy Policy · Acceptable Use Policy

Need something specific for your evaluation?

Compliance questionnaire, DPA request, penetration test report, subprocessor list — we're set up to respond.

Request security documentation →

SOC 2 controls and audit posture

CORE builds software with SOC 2 control requirements designed in at blueprint stage, and every system it produces carries those controls with the evidence an auditor will ask for. To be unambiguous about the other question people mean when they ask about SOC 2: SSDB Tech does not hold its own SOC 2 attestation and has not applied for one. We would rather say that plainly here than have you find it in a security review. If your procurement process requires a full security questionnaire, we complete standard formats (CAIQ, SIG) on request.

Data handling — encryption, residency, and no training on customer code

Customer code and prompts are not used to train foundation models by default. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). US data residency is standard; additional regions available under enterprise contract. Bring-your-own-key and bring-your-own-model paths supported on enterprise deployments.

Access controls — SSO, SAML, RBAC, and audit logs

Enterprise deployments include SAML SSO, role-based access control with least-privilege defaults, and audit logs on every action (generation, review, approval, deployment). Every action carries a named human identity in the audit trail. This is the artefact your SOC 2 auditor asks for.

Human-in-the-loop review as a control, not a feature

The human review gate is architected in, not bolted on. There is no configuration option to remove it. This is deliberate — a control your auditor can verify without taking our word for it.

Requesting our security documentation

To request our current security package (control summary, penetration test summaries, CAIQ / SIG responses, DPA templates), email security@ssdbtech.com. We respond within one business day.

Responsible disclosure

Security researchers: please email security@ssdbtech.com with details of any suspected vulnerability. We follow responsible disclosure practice and will acknowledge receipt within one business day.