Security & Trust

Protected by design.

How CoreID protects your data and governance records.

Data protection & isolation

  • Encryption in transit - all communications secured with TLS/HTTPS.
  • Encryption at rest - AWS RDS (PostgreSQL) and S3 encrypted at rest.
  • Organization isolation - membership validated on every API request; queries scoped by organization ID; cross-organization access is denied.
  • Data residency - documents and records stored in AWS (S3 and RDS) in the EU region.

Access control

  • Role-based access - 8 defined roles govern what each user can view, create, review and approve.
  • Separation of duty - in multi-user setups, the submitter can't be the approver.
  • Session management - configurable timeout policies.
  • MFA - multi-factor authentication available for accounts.

Audit & traceability

  • Audit trail - every governance action is recorded with a timestamp and the change detail. The platform provides no way to edit or delete these records.
  • Version history - every record keeps a full history of prior states.
  • Chronological event chain - events recorded in sequence for forensic reconstruction.

AI behavior & isolation

  • Stateless per request - AI requests don't persist context between requests.
  • No cross-user influence - each request carries only the requesting org's data.
  • Non-training - no customer data trains AI models (Anthropic commercial API).
  • Assistive only - AI supports workflows; all outputs require human review.
  • Org-level control - AI assistance can be disabled entirely per organization.

Infrastructure & storage

  • Cloud hosting - core data in AWS, EU region (Frankfurt).
  • Database - PostgreSQL via AWS RDS; tenant isolation in the application layer.
  • File storage - AWS S3 with short-lived, signed pre-signed URLs; path-traversal protections.
  • Rate limiting - applied to authentication and other protected endpoints.

Testing & validation

  • Adversarial testing - simulated attacks incl. permission-escalation, hostile payloads, cross-org probes.
  • Authentication coverage - enforcement routinely tested across APIs and protected routes.
  • AI trust boundary - tested for prompt injection, invalid output and hallucination; AI-suggested values validated against the schema.

CoreID provides governance infrastructure. It does not certify compliance, interpret law, or act as a regulatory authority.

Organizations retain full responsibility for their regulatory and legal obligations.

Security inquiries
support@coreidregistry.org
CoreID

The identity-anchored system of record. CoreID does not provide legal services.

Resources

Company

Legal

© 2026 CoreID · Velari Protocol Pty Ltd · ABN 17 685 666 586Enterprises remain responsible for their own regulatory compliance.