August 19, 2026

Security Overview

This overview describes CivCore’s approach to protecting customer data and is provided for customer diligence purposes.

August 19, 2026

Security Overview

This overview describes CivCore’s approach to protecting customer data and is provided for customer diligence purposes.

August 19, 2026

Security Overview

This overview describes CivCore’s approach to protecting customer data and is provided for customer diligence purposes.

1

Infrastructure and Hosting

CivCore is delivered as a web application hosted on leading cloud providers, including Amazon Web Services and Google Cloud Platform. All customer data is hosted in the United States.

2

Data Protection

CivCore applies technical and organizational controls to protect customer information:

  • Data is encrypted in transit using TLS 1.2 or higher.

  • Data is encrypted at rest.

  • Application-level authorization controls ensure each customer organization can access only its own data.

  • Access to production systems is restricted to authorized personnel, protected by multi-factor authentication, and logged.

3

AI Data Handling

CivCore uses large language models from Amazon Web Services, Google Cloud, and OpenAI to power its analysis features. Customer data is never used to train these providers’ models: our provider accounts are configured with model training disabled. Providers may temporarily retain submitted data under their standard API terms, after which it is deleted. CivCore does not train its own models on customer data without express customer agreement.

4

Compliance

CivCore’s SOC 2 Type II examination is in progress in partnership with Oneleet, with ISO 27001 certification planned to follow. Our SOC 2 report will be available to customers under NDA upon completion. Visit our trust center at security.civcore.com, or contact support@civcore.com for security documentation.

5

Data Ownership, Retention, and Deletion

CivCore’s data practices are designed to keep customers in control:

  • Customers own their data. CivCore uses it only to provide the service, as set out in our Terms of Service.

  • Customer data is retained for the duration of the subscription and, after termination, retained to allow account reactivation unless the customer requests deletion.

  • Customers may request deletion of some or all of their data at any time; deletion requests are completed within 90 days, subject to a 90-day backup cycle.

6

Subprocessors

We maintain a current list of subprocessors that process customer data, including our cloud, infrastructure, and AI providers, at civcore.com/legal/subprocessors. We notify customers before adding subprocessors and impose contractual data protection obligations on each of them. Our document-processing vendor, Datalab, processes documents transiently: uploads are deleted when the processing job completes. Our analytics and error-monitoring tools receive usage telemetry only; customer document content does not appear in them.

7

Incident Response

CivCore maintains an incident response process with defined roles and escalation paths. In the event of a confirmed security breach affecting customer data, we notify affected customers without undue delay in accordance with our Data Processing Addendum and applicable law.

8

Vulnerability Management

We monitor our applications and dependencies for vulnerabilities and apply security patches on a defined cadence. A third-party penetration test is scheduled; completion timing and summary availability will be published once verified.

9

Questions

Security questions and vulnerability reports: support@civcore.com. Trust center: security.civcore.com. We respond to customer security questionnaires as part of enterprise procurement.

The detailed version of security overview is provided under NDA.

Powering Projects

Across Continents

HQ
US
EUROPE
ASIA

Powering Projects

Across Continents

HQ
US
EUROPE
ASIA