Enterprise Security Standards
How Cora protects commercial shoot media, contract vaults, and financial ledgers with military-grade encryption.
AES-256 & TLS 1.3 Encryption
Every shoot photo, 4K video asset, and PDF invoice is encrypted using 256-bit Advanced Encryption Standard at rest and enforced via TLS 1.3 in transit.
SHA-256 Cryptographic E-Signs
Client signatures generate immutable cryptographic hash stamps with signer IP, timestamp, and device fingerprint compliant with the Indian IT Act 2000.
Multi-Tenant Row Level Isolation
Zero cross-tenant data leakage. Database queries enforce strict tenant boundaries and granular role-based permissions (Super Admin, Studio Owner, Crew Member).
Zero AI Training Guarantee
Proprietary contracts, rate cards, and financial balances are strictly segregated and never submitted into training sets for public AI models.
1. Compliance & Regulatory Standards
Cora is engineered to meet stringent global and Indian regulatory requirements:
- Indian IT Act 2000 (Section 65B): Digital contract admissibility in commercial arbitration and legal courts.
- GST Tax Engine Verification: 18% CGST/SGST/IGST tax calculation engine adheres to CBIC invoicing guidelines.
- SOC-2 Type II Readiness: Continuous internal controls monitoring for security, availability, and confidentiality.
- GDPR & DPDP Act 2023: Full user rights to data portability, export, and complete workspace deletion.
2. Infrastructure & Data Center Resilience
Our production infrastructure is hosted across Tier-4 data centers with automated daily offsite snapshots, geo-redundant backups, and 99.95% guaranteed uptime.
3. Responsible Vulnerability Disclosure
We welcome reports from independent security researchers. If you discover a potential vulnerability, please email our security engineering desk: