Loading…
Loading…
Security & Trust
Security documentation is often locked behind sales calls. We think that's wrong. Here's exactly where we stand, including what's in progress.
Data Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are rotated quarterly and managed via cloud KMS.
Isolated Scan Jobs
Scan workers execute jobs independently, apply per-project configuration, and persist only the resulting findings and metadata.
Tenant-Scoped Access
Project, scan, and issue endpoints enforce tenant and project scoping so data remains isolated to authorized workspace members.
Privacy Obligations
We implement controls aligned with GDPR and CCPA obligations. We offer Data Processing Agreements (DPA) to all customers, and data residency options are available on enterprise plans.
SOC 2 Type II
Our SOC 2 Type II audit is underway. Current controls include role-based access, encryption at rest and in transit, and regular third-party penetration testing.
Vulnerability Disclosure
We operate a responsible disclosure program. Report issues to security@coreaccessibility.com. We respond within 24 hours and patch critical issues within 72 hours.
Implemented Controls
API scan triggers require a valid project API key. Keys are checked before enqueuing scan jobs, and archived projects cannot trigger new runs.
Project-level authentication and integration settings are encrypted at rest in the application layer before storage.
Captured screenshots are stored per scan and referenced by issue/page records, keeping artifacts segmented by workspace and run.
Issue status changes, validation actions, comments, and scan run history create an auditable trail for internal and external review.
Our SOC 2 bridge letter, penetration test summary, DPA, and sub-processor list are available on request. We typically respond within one business day.
Free scan takes 2 minutes. No credit card required.