Security and compliance built for enterprise procurement
CORE is designed to SOC 2 controls: SSO/SAML, role-based access, encryption at rest and in transit, audit logs on every action, and no training on customer code by default. Below is the full posture. Documentation available on request under NDA.
Zero Retention — the single most important thing to know
Nothing you share with CORE — your business requirements, uploaded documents, existing code, or the software CORE generates — is ever used to train, fine-tune, or improve any AI model. Ever.
Your data stays inside your project's boundary. Access is limited to systems that directly serve your build. When your engagement ends, your data is deleted according to a documented retention schedule. What CORE builds for you is yours alone — permanently.
Security built into every layer
CORE's security posture is defense-in-depth, not perimeter-only. Each layer has its own controls, monitored independently.
- TLS 1.3 for data in transit (TLS 1.2 minimum for legacy clients)
- AES-256 for data at rest
- Envelope encryption with regular key rotation
- Secrets managed via dedicated secret management systems (never in code, config, or logs)
- SAML 2.0 / OIDC single sign-on (Okta, Azure AD, Google Workspace)
- Multi-factor authentication enforced for administrative access
- Role-based access controls with segregation of duties
- All administrative actions logged with immutable audit trails
- Append-only audit logs across data-affecting operations
- Configurable retention (typical: 7 years for SOX-scope data)
- Log integrity monitoring against tampering
- Access logs available for customer-side review
- Input validation and output encoding
- SQL-injection, XSS, and CSRF mitigations built in
- Rate limiting and abuse prevention
- Prompt injection defense at AI layer
- Deployed on major cloud providers (AWS, Azure, GCP) at customer choice
- Configurable data residency (US, EU, UK, APAC)
- Cloudflare edge protection (bot mitigation, DDoS)
- Automated backups with tested restoration
- 24-hour customer notification for confirmed security incidents affecting them
- Documented containment, eradication, and recovery playbooks
- Post-incident review and customer-facing report
- Responsible disclosure program via report@ssdbtech.com
Compliance frameworks CORE aligns with
Every system CORE builds has the relevant controls designed in at blueprint stage rather than retrofitted before an audit — so the software you receive is built to satisfy the frameworks below, with the control mappings and evidence produced alongside it. These are statements about the software CORE builds for you, not claims that SSDB Tech holds third-party certifications of its own — we hold none, and we say so further down this page rather than leaving it to inference.
CONTROLS
27001
800-53
DPDP
DSS
Responsible disclosure
Security researchers and customers who identify a potential vulnerability can report it confidentially to report@ssdbtech.com. We respond within 48 hours and follow a documented triage and remediation process.
Detailed policy documents: Security Policy · Privacy Policy · Acceptable Use Policy
Need something specific for your evaluation?
Compliance questionnaire, DPA request, penetration test report, subprocessor list — we're set up to respond.
Request security documentation →SOC 2 controls and audit posture
CORE builds software with SOC 2 control requirements designed in at blueprint stage, and every system it produces carries those controls with the evidence an auditor will ask for. To be unambiguous about the other question people mean when they ask about SOC 2: SSDB Tech does not hold its own SOC 2 attestation and has not applied for one. We would rather say that plainly here than have you find it in a security review. If your procurement process requires a full security questionnaire, we complete standard formats (CAIQ, SIG) on request.
Data handling — encryption, residency, and no training on customer code
Customer code and prompts are not used to train foundation models by default. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). US data residency is standard; additional regions available under enterprise contract. Bring-your-own-key and bring-your-own-model paths supported on enterprise deployments.
Access controls — SSO, SAML, RBAC, and audit logs
Enterprise deployments include SAML SSO, role-based access control with least-privilege defaults, and audit logs on every action (generation, review, approval, deployment). Every action carries a named human identity in the audit trail. This is the artefact your SOC 2 auditor asks for.
Human-in-the-loop review as a control, not a feature
The human review gate is architected in, not bolted on. There is no configuration option to remove it. This is deliberate — a control your auditor can verify without taking our word for it.
Requesting our security documentation
To request our current security package (control summary, penetration test summaries, CAIQ / SIG responses, DPA templates), email security@ssdbtech.com. We respond within one business day.
Responsible disclosure
Security researchers: please email security@ssdbtech.com with details of any suspected vulnerability. We follow responsible disclosure practice and will acknowledge receipt within one business day.