Security & Trust
Protected by design.
How CoreID protects your data and governance records.
Data protection & isolation
- Encryption in transit - all communications secured with TLS/HTTPS.
- Encryption at rest - AWS RDS (PostgreSQL) and S3 encrypted at rest.
- Organization isolation - membership validated on every API request; queries scoped by organization ID; cross-organization access is denied.
- Data residency - documents and records stored in AWS (S3 and RDS) in the EU region.
Access control
- Role-based access - 8 defined roles govern what each user can view, create, review and approve.
- Separation of duty - in multi-user setups, the submitter can't be the approver.
- Session management - configurable timeout policies.
- MFA - multi-factor authentication available for accounts.
Audit & traceability
- Audit trail - every governance action is recorded with a timestamp and the change detail. The platform provides no way to edit or delete these records.
- Version history - every record keeps a full history of prior states.
- Chronological event chain - events recorded in sequence for forensic reconstruction.
AI behavior & isolation
- Stateless per request - AI requests don't persist context between requests.
- No cross-user influence - each request carries only the requesting org's data.
- Non-training - no customer data trains AI models (Anthropic commercial API).
- Assistive only - AI supports workflows; all outputs require human review.
- Org-level control - AI assistance can be disabled entirely per organization.
Infrastructure & storage
- Cloud hosting - core data in AWS, EU region (Frankfurt).
- Database - PostgreSQL via AWS RDS; tenant isolation in the application layer.
- File storage - AWS S3 with short-lived, signed pre-signed URLs; path-traversal protections.
- Rate limiting - applied to authentication and other protected endpoints.
Testing & validation
- Adversarial testing - simulated attacks incl. permission-escalation, hostile payloads, cross-org probes.
- Authentication coverage - enforcement routinely tested across APIs and protected routes.
- AI trust boundary - tested for prompt injection, invalid output and hallucination; AI-suggested values validated against the schema.
CoreID provides governance infrastructure. It does not certify compliance, interpret law, or act as a regulatory authority.
Organizations retain full responsibility for their regulatory and legal obligations.
Security inquiries
support@coreidregistry.org