Korinza Trust Center — Security & Privacy Practices

Korinza is a risk and compliance platform. We hold ourselves to the same standards we help our customers achieve.

Security Practices

Encryption in transit and at rest

All data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256. Encryption keys are managed by the cloud provider's key management service and rotated automatically.

Authentication and session management

Sessions are managed using signed JWTs with configurable expiry. OAuth 2.0 is used for third-party authentication. All authentication events are logged in the audit trail.

Role-based access controls

Every user has an explicit role: owner, admin, member, viewer, external auditor, or audit viewer. Permissions are enforced at the API layer, not just the UI. Auditors get read-only access to evidence — nothing more.

Full audit trail

Every create, update, and delete operation on risks, controls, policies, audits, and findings is logged with timestamp, user identity, and before/after values. The audit log is append-only and cannot be edited.

Infrastructure and availability

Korinza runs on managed cloud infrastructure with automated backups, health monitoring, and failover. Database backups are taken daily and retained for 30 days. We target 99.9% monthly uptime.

Dependency and vulnerability management

Dependencies are scanned for known vulnerabilities on every build. Critical vulnerabilities are patched within 48 hours of disclosure. We follow a responsible disclosure policy for security researchers.

Data residency

Customer data is stored in the United States. We do not transfer personal data to jurisdictions without adequate data protection frameworks. Data processing agreements (DPAs) are available on request.

Incident response

We maintain a documented incident response plan with defined escalation paths, communication templates, and post-incident review procedures. Customers are notified of material security incidents within 72 hours.

Data Privacy

Access Control Roles

RoleAccess Level
OwnerFull access to all settings, billing, and data. Can delete the organisation.
AdminFull access to all features. Cannot delete the organisation or change billing.
MemberCan create and edit risks, controls, policies, and audits. Cannot change org settings.
ViewerRead-only access to all data. Cannot create or edit anything.
External AuditorRead-only access to assigned audits, evidence, and findings. Cannot see other data.
Audit ViewerRead-only access to audit reports only. Scoped to specific audits.

Contact

Security questions or DPA requests: support@korinza.com