Former Microsoft Identity President, Joy Chik, Joins NewCore Board

Trust & Security

TrustisCore.

We earn the trust of our customers and partners through transparency, security, and compliance - backed by infrastructure built to the highest standards in identity security.

  • SOC 2
  • CSA STAR
  • CISA
  • GDPR
  • CCPA

Frameworks & Certifications

Independent attestationsand the frameworks we align to.

Third-party audits, regulatory alignment, and cross-border privacy — renewed on a schedule and available to security reviewers on request.

SOC 2

SOC 2 Type II

Annually audited. Controls span security, availability, and confidentiality.

CSA STAR

CSA STAR Level 1

Cloud Security Alliance Level 1 compliant.

CISA

CISA Secure-by-Design Pledge

Prioritizing the security of customers.

GDPR

GDPR

Compliant data processing with EU data residency options.

CCPA

CCPA

California Consumer Privacy Act compliant.

The Program

37 controls, six domains,one continuous program.

The Full Program

Every control we run,documented in plain language.

6 domains · 37 controls

Information Security Management

Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.

  • Security Leadership

    Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.

  • Information Security Policies and Procedures

    We maintain a comprehensive policy set, approved by management, reviewed at least annually, and available to all employees on our internal portal.

  • Background Checks

    All candidates undergo screening and reference checks as part of the hiring process, in accordance with local laws.

  • Employee Confidentiality

    All new hires sign an employment agreement covering confidentiality, code of conduct, and intellectual property.

  • Mandatory Security Awareness Training

    All employees complete security awareness training within 30 days of joining and annually thereafter, with additional role-specific training for higher-risk roles.

  • Risk Management Program

    We run a formal risk management program, led by the CISO, with an annual risk assessment and management-approved remediation.

  • Disciplinary Process

    A documented disciplinary process addresses violations of our security policies.

  • Independent Annual Audit

    We undergo an independent annual SOC 2 Type II examination by a qualified third-party CPA firm.

  • Cyber Insurance

    We maintain a cyber insurance policy with coverage appropriate to the scale and risk profile of our business.

Network & Infrastructure Security

Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.

  • High Availability & Auto-Scaling

    Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.

  • Logging & Monitoring

    All production activity is logged, centralized, and continuously monitored, with alerts triggered on anomalies.

  • Disaster Recovery

    Infrastructure and data are distributed across multiple availability zones with automated backups, and recovery is tested through an annual DR drill.

  • Least Privilege

    Access is provisioned by role and baselined regularly, with permissions to production, databases, and applications reviewed at least annually.

  • Production Environment Isolation

    The production environment is fully separated from the corporate environment, requiring two-factor authentication and IP filtering for access.

  • Network Security & Segmentation

    Resources are protected by firewalls, VPNs, encrypted tunnels, intrusion-detection monitoring, and least-privilege port configuration.

  • Infrastructure Provider Oversight

    We review our cloud provider's SOC 2 report annually and document the complementary controls we operate.

Data Privacy & Protection

All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.

  • Encryption at Rest

    All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.

  • Encryption in Transit

    All traffic is served over HTTPS and encrypted in transit using TLS 1.2+ with strong cipher suites.

  • Data Retention & Disposal

    Data retention and deletion follow customer contracts and applicable law, with customer data returned on termination and then securely erased.

  • Key Management

    Encryption keys are hardware-bound with unique keys per environment, automated rotation, dual authorization, and full lifecycle logging.

  • Data Classification & Inventory

    We classify data by sensitivity and maintain an inventory of sensitive and personal data, including owner, location, and processing purpose.

  • Privacy by Design & GDPR

    We apply data minimization and privacy impact assessments, maintain a disclosed sub-processor list, and notify the data controller of a personal data breach within 72 hours.

Incident Detection & Response

Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.

  • Code Review

    Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.

  • Incident Response Process

    We maintain a tested incident response plan with defined escalation, rapid mitigation, and post-incident root-cause analysis.

  • 24/7 Monitoring & Escalation

    Our Security team monitors production continuously, with a defined escalation matrix and time-bound response targets for critical alerts.

  • Vendor Risk Assessments

    We formally assess vendors and sub-processors at least annually, with a higher bar for those handling sensitive data or critical systems.

  • Breach Notification

    Breach notification procedures meet GDPR and customer-contractual SLAs and are documented in our Incident Response Policy and DPAs.

Product Security

Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.

  • Penetration Testing

    Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.

  • Single Sign-On & Authentication

    The platform supports SAML 2.0, OpenID Connect, OAuth 2.0, and LDAP/Active Directory, plus FIDO2 passkeys, hardware tokens, push, and one-time passwords.

  • Multi-Factor Authentication

    MFA is required for access to sensitive systems and for privileged access to sensitive data.

  • Secure Development Lifecycle

    We follow a documented SDLC with OWASP secure coding standards, mandatory code review, automated testing, and SAST and dependency scanning as CI gates.

  • Vulnerability Management

    Vulnerabilities are scanned continuously, prioritized using CVSS, and remediated against defined SLAs.

  • Change Management

    All production changes follow a documented change-control process with approval, testing, and a required rollback plan.

Endpoint Security

All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.

  • Endpoint Encryption

    All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.

  • Endpoint Management

    Employee devices are enrolled in MDM with enforced patching, screen lock, and managed configuration.

  • Antivirus & EDR

    Endpoint detection and response and antivirus run on all endpoints via a centralized tool with automatically updated signatures.

  • Remote Work & BYOD

    Remote-work and BYOD protections are governed by our Acceptable Use, BYOD, and Physical Security policies.

Know what exists.Know what needs action.

See how we discover identities beyond the IdP, resolve fragmented records into one current view, and trace the access paths that need review.