Security

Last updated July 26, 2026

Core is designed for institutions whose reporting must withstand audit. The security model prioritizes data residency, encryption, controlled access, and evidence integrity.

Encryption

All customer data is encrypted at rest and in transit. Transmitted data uses TLS across every connection. Stored data — including documents, indicators, artifacts, and provenance records — is encrypted with managed key infrastructure.

Data residency

Core operates exclusively in the Canada Central (ca-central-1) AWS region, selected for Canadian data residency and its lower-carbon grid. No cross-region replication is enabled. The regional residency of every processing step is verified before it is permitted, and the system fails closed rather than falling back to a non-Canadian region.

Access control

Access is invite-only. Accounts are provisioned by an authorized administrator; there is no open registration. Authentication requires verified credentials, and privileged roles require multi-factor authentication. Customers interact exclusively through the Core web application and Core OAuth APIs — no customer receives direct infrastructure access, cloud console credentials, or internal endpoint addresses.

Evidence integrity

Every published indicator, artifact version, and provenance record is content-addressed and immutable. Source materials are stored as versioned revisions. A value cited in a report can be reconstructed from its recorded sources at any time; superseded or withdrawn sources are excluded from verification unless an explicit historical-audit mode is requested.

Operational security

Internal engineering access is separated from customer access and governed by workforce identities under distinct controls. All administrative actions are logged. Customer conversations are not monitored or reviewed by staff unless support is explicitly requested and access granted.

Reporting a concern

If you identify a security issue or have a question about this page, contact the platform administrator directly. This overview will be updated as practices evolve.