This overview describes CivCore’s approach to protecting customer data. It is general information provided for information only. Civcore’s binding commitments are set out in our Terms of Service and Data Processing Addendum, and this page is not incorporated into those agreements or offered as a warranty. Detailed security documentation, including our SOC 2 report when available, is provided to customers and prospective customers under a non-disclosure agreement on request.
1
Infrastructure and Hosting
CivCore is delivered as a web application hosted on established commercial cloud providers, including Amazon Web Services and Google Cloud Platform. All customer data is hosted in the United States.
2
AI Data Handling
CivCore uses large language models from established providers to power its analysis features. Customer data is never used to train these providers’ models: our provider accounts are configured with model training disabled. Providers may temporarily retain submitted data under their standard API terms, (for example, for abuse monitoring), after which it is deleted. CivCore does not train its own models on customer data without express customer agreement.
3
Compliance
CivCore’s SOC 2 Type II examination is in progress in partnership with Oneleet, with ISO 27001 certification planned to follow. Our SOC 2 report will be available to customers under NDA upon completion. Visit our trust center at security.civcore.com, or contact support@civcore.com for security documentation.
4
Data Ownership, Retention, and Deletion
Customers own their data. CivCore uses it only to provide the service, as set out in our Terms of Service.
Customer data is retained for the duration of the subscription and, after termination, retained to allow account reactivation unless the customer requests deletion.
Customers may request deletion of some or all of their data at any time; deletion requests are completed within 90 days, subject to a 90-day backup cycle.
5
Subprocessors
We maintain a current list of subprocessors that process customer data where customers can subscribe to email notifications of changes. CivCore will provide subprocessors if requested.
6
Security Program and Compliance
CivCore maintains a documented security program covering access management, change management, vulnerability management, vendor management, and incident response. Our SOC 2 Type II examination is in progress with Oneleet. Independent security testing is performed by a third party. Program details, testing results, and our SOC 2 report when available are shared with customers under NDA.
7
Incident Response
CivCore maintains an incident response process with defined roles and escalation paths. In the event of a confirmed security breach affecting customer data, we notify affected customers without undue delay in accordance with our Data Processing Addendum and applicable law.
8
Vulnerability Management
We monitor our applications and dependencies for vulnerabilities and apply security patches on a defined cadence. The most recent third-party penetration test is completed successfully on August 6, 2026. Report is available upon request.
9
Questions
Security questions and vulnerability reports: support@civcore.com. Trust center: security.civcore.com. We respond to customer security questionnaires as part of enterprise procurement.