Security

At CoreVitals, security is a foundational design principle. Our platform is built to protect the confidentiality, integrity, and availability of customer data through layered technical, administrative, and operational controls. We continuously evaluate and improve our security posture to address evolving threats and industry best practices.

Data Encryption

Encryption in Transit

All communication between clients, APIs, and our platform is encrypted using TLS 1.3. This ensures that data transmitted over public networks is protected against interception and tampering.

Encryption at Rest

Customer data is encrypted at rest using AES-256 encryption. Storage systems, databases, and backups are encrypted to help protect information from unauthorized access.

Per-Tenant Encryption

Each customer is protected with unique encryption keys. Tenant isolation extends beyond logical separation by ensuring encrypted customer data cannot be decrypted using another customer's key.

Evidence Encryption

Evidence uploaded to CoreVitals is individually encrypted before being stored. This provides an additional layer of protection beyond storage-level encryption and limits the impact of any potential storage compromise.

Key Management

Encryption keys are managed through Google Cloud Key Management Service (Cloud KMS). Keys are securely generated, stored, rotated, and protected using Google's managed hardware-backed infrastructure.

Identity and Access Management

Multi-Factor Authentication

Multi-factor authentication (MFA) is mandatory for all user accounts. Access to the platform requires both a password and an additional authentication factor.

Role-Based Access Control

CoreVitals implements role-based access control (RBAC), allowing organizations to assign permissions based on job responsibilities. Users receive only the minimum level of access necessary to perform their work.

Monitoring and Detection

Infrastructure Monitoring

Our infrastructure is continuously monitored for availability, performance, and security-related events. Monitoring enables rapid detection of operational issues and potential security concerns.

Continuous Vulnerability Scanning

We continuously scan our applications, infrastructure, and software dependencies for known vulnerabilities. Identified issues are prioritized according to risk and remediated through our vulnerability management process.

Immutable Audit Logs

Security-sensitive events and customer actions are recorded in tamper-resistant audit logs. Audit records support compliance, forensic investigations, and accountability.

Secure Development

Security is integrated throughout our software development lifecycle.

Our engineering practices include:

  • Secure code reviews
  • Static application security testing (SAST)
  • Dependency vulnerability scanning
  • Secret detection
  • Automated security testing
  • Security-focused release reviews

Security defects are prioritized based on severity and addressed before production deployment whenever practical.

Secrets Management

Application secrets, credentials, encryption keys, and service accounts are never stored within source code repositories. Secrets are securely managed using centralized secrets management services with strict access controls and auditing.

Backups and Disaster Recovery

Encrypted Backups

Customer data is backed up daily using encrypted backup processes. Backup data is protected using the same security standards applied to production systems.

Disaster Recovery

CoreVitals maintains documented disaster recovery procedures designed to restore critical services following significant operational disruptions. Recovery procedures are periodically reviewed and tested to improve operational readiness.

Security Operations

Incident Response

CoreVitals maintains a documented incident response process for identifying, investigating, containing, eradicating, and recovering from security incidents.

When a confirmed security incident materially impacts customer data, affected customers will be notified without undue delay in accordance with applicable legal and contractual obligations.

Vendor Risk Management

We carefully evaluate third-party service providers that process or store customer data. Vendors are selected based on their security posture, contractual commitments, and operational reliability. Access granted to vendors is limited to what is necessary for the services they provide.

Independent Security Assessments

CoreVitals undergoes annual independent penetration testing to evaluate the security of our platform. Findings are reviewed, prioritized, and remediated according to our vulnerability management process.

Responsible Disclosure

We welcome reports from security researchers who discover potential vulnerabilities in our platform.

If you believe you have identified a security issue, please report it responsibly by emailing security@corevitals.com. Please include sufficient information to reproduce the issue and avoid accessing, modifying, or disclosing customer data.

We request that researchers:

  • Give us a reasonable opportunity to investigate and remediate reported vulnerabilities before public disclosure.
  • Avoid disrupting production services.
  • Respect customer privacy and confidentiality.
  • Refrain from exploiting vulnerabilities beyond what is necessary to demonstrate their existence.

We review all legitimate reports and work promptly to investigate and resolve confirmed issues.

Shared Responsibility

While CoreVitals provides a secure platform, security is a shared responsibility. Customers are responsible for:

  • Protecting account credentials.
  • Managing user access and permissions.
  • Enabling and maintaining multi-factor authentication.
  • Promptly disabling accounts that no longer require access.
  • Reviewing audit logs and user activity.
  • Ensuring data uploaded to the platform complies with applicable legal and regulatory requirements.

Questions

Security questions may be directed to security@corevitals.com.