Meet Us at Black Hat USA 2026Book a Meeting
NewCore

Trust & Security

We earn the trust of our customers and partners through transparency, security, and compliance - backed by infrastructure built to the highest standards in identity security.

  • SOC 2
  • CSA STAR
  • CISA
  • GDPR
  • CCPA

Frameworks & Certifications

Independent attestationsand the frameworks we align to.

Third-party audits, regulatory alignment, and cross-border privacy, renewed on a schedule and available to security reviewers on request.

  • SOC 2

    SOC 2 Type II

    Annually audited. Controls span security, availability, and confidentiality.

  • CSA STAR

    CSA STAR Level 1

    Cloud Security Alliance Level 1 compliant.

  • CISA

    CISA Secure-by-Design Pledge

    Prioritizing the security of customers.

  • GDPR

    GDPR

    Compliant data processing with EU data residency options.

  • CCPA

    CCPA

    California Consumer Privacy Act compliant.

  • ReviewersRequest our reports & DPIA package.Contact security

The Program

37 controls, six domains,one continuous program.

View all 37 controls

The Full Program

Every control we run,documented in plain language.

6 domains · 37 controls

Information Security Management

Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.

Security Leadership

Our CISO owns the information security program, supported by a Security Steering Committee and quarterly Board oversight.

Information Security Policies and Procedures

We maintain a comprehensive policy set, approved by management, reviewed at least annually, and available to all employees on our internal portal.

Background Checks

All candidates undergo screening and reference checks as part of the hiring process, in accordance with local laws.

Employee Confidentiality

All new hires sign an employment agreement covering confidentiality, code of conduct, and intellectual property.

Mandatory Security Awareness Training

All employees complete security awareness training within 30 days of joining and annually thereafter, with additional role-specific training for higher-risk roles.

Risk Management Program

We run a formal risk management program, led by the CISO, with an annual risk assessment and management-approved remediation.

Disciplinary Process

A documented disciplinary process addresses violations of our security policies.

Independent Annual Audit

We undergo an independent annual SOC 2 Type II examination by a qualified third-party CPA firm.

Cyber Insurance

We maintain a cyber insurance policy with coverage appropriate to the scale and risk profile of our business.

Network & Infrastructure Security

Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.

High Availability & Auto-Scaling

Our cloud infrastructure runs across multiple availability zones and auto-scales to maintain availability under demand.

Logging & Monitoring

All production activity is logged, centralized, and continuously monitored, with alerts triggered on anomalies.

Disaster Recovery

Infrastructure and data are distributed across multiple availability zones with automated backups, and recovery is tested through an annual DR drill.

Least Privilege

Access is provisioned by role and baselined regularly, with permissions to production, databases, and applications reviewed at least annually.

Production Environment Isolation

The production environment is fully separated from the corporate environment, requiring two-factor authentication and IP filtering for access.

Network Security & Segmentation

Resources are protected by firewalls, VPNs, encrypted tunnels, intrusion-detection monitoring, and least-privilege port configuration.

Infrastructure Provider Oversight

We review our cloud provider's SOC 2 report annually and document the complementary controls we operate.

Data Privacy & Protection

All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.

Encryption at Rest

All data at rest is encrypted with AES-256 using hardware-bound keys, with no action required from customers.

Encryption in Transit

All traffic is served over HTTPS and encrypted in transit using TLS 1.2+ with strong cipher suites.

Data Retention & Disposal

Data retention and deletion follow customer contracts and applicable law, with customer data returned on termination and then securely erased.

Key Management

Encryption keys are hardware-bound with unique keys per environment, automated rotation, dual authorization, and full lifecycle logging.

Data Classification & Inventory

We classify data by sensitivity and maintain an inventory of sensitive and personal data, including owner, location, and processing purpose.

Privacy by Design & GDPR

We apply data minimization and privacy impact assessments, maintain a disclosed sub-processor list, and notify the data controller of a personal data breach within 72 hours.

Incident Detection & Response

Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.

Code Review

Every pull request undergoes mandatory peer review, documented in our source-control tool, before it can be merged.

Incident Response Process

We maintain a tested incident response plan with defined escalation, rapid mitigation, and post-incident root-cause analysis.

24/7 Monitoring & Escalation

Our Security team monitors production continuously, with a defined escalation matrix and time-bound response targets for critical alerts.

Vendor Risk Assessments

We formally assess vendors and sub-processors at least annually, with a higher bar for those handling sensitive data or critical systems.

Breach Notification

Breach notification procedures meet GDPR and customer-contractual SLAs and are documented in our Incident Response Policy and DPAs.

Product Security

Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.

Penetration Testing

Independent third-party experts perform a detailed penetration test of the application and infrastructure at least annually, with critical and high findings resolved.

Single Sign-On & Authentication

The platform supports SAML 2.0, OpenID Connect, OAuth 2.0, and LDAP/Active Directory, plus FIDO2 passkeys, hardware tokens, push, and one-time passwords.

Multi-Factor Authentication

MFA is required for access to sensitive systems and for privileged access to sensitive data.

Secure Development Lifecycle

We follow a documented SDLC with OWASP secure coding standards, mandatory code review, automated testing, and SAST and dependency scanning as CI gates.

Vulnerability Management

Vulnerabilities are scanned continuously, prioritized using CVSS, and remediated against defined SLAs.

Change Management

All production changes follow a documented change-control process with approval, testing, and a required rollback plan.

Endpoint Security

All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.

Endpoint Encryption

All corporate devices use full-disk AES-256 encryption enforced via MDM and can be remotely wiped if lost or compromised.

Endpoint Management

Employee devices are enrolled in MDM with enforced patching, screen lock, and managed configuration.

Antivirus & EDR

Endpoint detection and response and antivirus run on all endpoints via a centralized tool with automatically updated signatures.

Remote Work & BYOD

Remote-work and BYOD protections are governed by our Acceptable Use, BYOD, and Physical Security policies.

Know what exists.
Know what needs action.

See how we discover identities beyond the IdP, resolve fragmented records into one current view, and trace the access paths that need review.