Korinza Trust Center — Security & Privacy Practices
Korinza is a risk and compliance platform. We hold ourselves to the same standards we help our customers achieve.
Security Practices
Encryption in transit and at rest
All data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256. Encryption keys are managed by the cloud provider's key management service and rotated automatically.
Authentication and session management
Sessions are managed using signed JWTs with configurable expiry. OAuth 2.0 is used for third-party authentication. All authentication events are logged in the audit trail.
Role-based access controls
Every user has an explicit role: owner, admin, member, viewer, external auditor, or audit viewer. Permissions are enforced at the API layer, not just the UI. Auditors get read-only access to evidence — nothing more.
Full audit trail
Every create, update, and delete operation on risks, controls, policies, audits, and findings is logged with timestamp, user identity, and before/after values. The audit log is append-only and cannot be edited.
Infrastructure and availability
Korinza runs on managed cloud infrastructure with automated backups, health monitoring, and failover. Database backups are taken daily and retained for 30 days. We target 99.9% monthly uptime.
Dependency and vulnerability management
Dependencies are scanned for known vulnerabilities on every build. Critical vulnerabilities are patched within 48 hours of disclosure. We follow a responsible disclosure policy for security researchers.
Data residency
Customer data is stored in the United States. We do not transfer personal data to jurisdictions without adequate data protection frameworks. Data processing agreements (DPAs) are available on request.
Incident response
We maintain a documented incident response plan with defined escalation paths, communication templates, and post-incident review procedures. Customers are notified of material security incidents within 72 hours.
Data Privacy
- We collect only the data necessary to provide the service — no behavioural advertising, no data brokering.
- Customer data is never used to train AI models without explicit opt-in.
- You can request a full export of your organisation's data at any time.
- You can request deletion of your organisation's data at any time. Deletion is completed within 30 days.
- Sub-processors are listed in our Data Processing Agreement, available on request.
- We are GDPR-aware and provide DPAs for EU customers.
Access Control Roles
| Role | Access Level |
|---|---|
| Owner | Full access to all settings, billing, and data. Can delete the organisation. |
| Admin | Full access to all features. Cannot delete the organisation or change billing. |
| Member | Can create and edit risks, controls, policies, and audits. Cannot change org settings. |
| Viewer | Read-only access to all data. Cannot create or edit anything. |
| External Auditor | Read-only access to assigned audits, evidence, and findings. Cannot see other data. |
| Audit Viewer | Read-only access to audit reports only. Scoped to specific audits. |
Contact
Security questions or DPA requests: support@korinza.com