August 19, 2026

Security Overview

This overview describes CivCore's approach to protecting customer data.

August 19, 2026

Security Overview

This overview describes CivCore's approach to protecting customer data.

August 19, 2026

Security Overview

This overview describes CivCore's approach to protecting customer data.

This overview describes CivCore’s approach to protecting customer data. It is general information provided for information only. Civcore’s binding commitments are set out in our Terms of Service and Data Processing Addendum, and this page is not incorporated into those agreements or offered as a warranty. Detailed security documentation, including our SOC 2 report when available, is provided to customers and prospective customers under a non-disclosure agreement on request.

1

Infrastructure and Hosting

CivCore is delivered as a web application hosted on established commercial cloud providers, including Amazon Web Services and Google Cloud Platform. All customer data is hosted in the United States.

2

AI Data Handling

CivCore uses large language models from established providers to power its analysis features. Customer data is never used to train these providers’ models: our provider accounts are configured with model training disabled. Providers may temporarily retain submitted data under their standard API terms, (for example, for abuse monitoring), after which it is deleted. CivCore does not train its own models on customer data without express customer agreement.

3

Compliance

CivCore’s SOC 2 Type II examination is in progress in partnership with Oneleet, with ISO 27001 certification planned to follow. Our SOC 2 report will be available to customers under NDA upon completion. Visit our trust center at security.civcore.com, or contact support@civcore.com for security documentation.

4

Data Ownership, Retention, and Deletion

  • Customers own their data. CivCore uses it only to provide the service, as set out in our Terms of Service.

  • Customer data is retained for the duration of the subscription and, after termination, retained to allow account reactivation unless the customer requests deletion.

  • Customers may request deletion of some or all of their data at any time; deletion requests are completed within 90 days, subject to a 90-day backup cycle.

5

Subprocessors

We maintain a current list of subprocessors that process customer data where customers can subscribe to email notifications of changes. CivCore will provide subprocessors if requested.

6

Security Program and Compliance

CivCore maintains a documented security program covering access management, change management, vulnerability management, vendor management, and incident response. Our SOC 2 Type II examination is in progress with Oneleet. Independent security testing is performed by a third party. Program details, testing results, and our SOC 2 report when available are shared with customers under NDA.

7

Incident Response

CivCore maintains an incident response process with defined roles and escalation paths. In the event of a confirmed security breach affecting customer data, we notify affected customers without undue delay in accordance with our Data Processing Addendum and applicable law.

8

Vulnerability Management

We monitor our applications and dependencies for vulnerabilities and apply security patches on a defined cadence. The most recent third-party penetration test is completed successfully on August 6, 2026. Report is available upon request.

9

Questions

Security questions and vulnerability reports: support@civcore.com. Trust center: security.civcore.com. We respond to customer security questionnaires as part of enterprise procurement.

Powering Projects

Across Continents

HQ
US
EUROPE
ASIA
MIDDLE EAST

Powering Projects

Across Continents

HQ
US
EUROPE
ASIA
MIDDLE EAST