CORA
SECURITY ARCHITECTURE & COMPLIANCE

Enterprise Security Standards

How Cora protects professional business records, contract vaults, client documents, and financial ledgers with military-grade encryption.

AES-256 & TLS 1.3 Encryption

Every business record, client document, asset deliverable, and PDF invoice is encrypted using 256-bit Advanced Encryption Standard at rest and enforced via TLS 1.3 in transit.

SHA-256 Cryptographic E-Signs

Client signatures generate immutable cryptographic hash stamps with signer IP, timestamp, and device fingerprint compliant with the Indian IT Act 2000.

Zero AI Training Guarantee

Your business proposals, financial ledgers, and client records are zero-retention processed. We never use proprietary tenant data to train base models.

100% Indian Data Residency

Primary production databases and file storage are hosted in Tier-4 data centers in Mumbai, complying strictly with Indian DPDP Act 2023 guidelines.

1. Multi-Tenant Row-Level Isolation (RLS)

Cora utilizes database-level Row Level Security (RLS). Every query executed by our application layer is bounded by your unique workspace_id. It is mathematically impossible for one business tenant to view, leak, or mutate records from another organization.

2. Vulnerability Testing & Bug Bounty

We conduct automated static analysis, dynamic AST penetration testing, and annual third-party security audits. If you discover a security vulnerability, please report it responsibly to security@heycora.in for immediate escalation.