CORO
FRRequest a demo
Security & data protection

Security is part of the architecture.

CORO is designed for organizations that need to protect sensitive documents, control access and keep their data in Canada. Our approach combines Canadian hosting, encrypted communications, access control, backups and monitoring.

Canadian hosting. Controlled access. Encrypted communications. Automated backups.

An approach designed for professional environments

CORO security relies on complementary layers, from infrastructure to access management.

Data hosted in Canada

Platform data and documents are hosted on infrastructure located in Toronto, Ontario, supporting Canadian organizations’ data-sovereignty requirements.

Encrypted communications

Traffic between users and the platform is protected with HTTPS/TLS. Passwords are stored in hashed form and are not kept in plain text.

Access control

Permissions are assigned according to user roles. Customer environments are isolated to restrict data access to authorized users.

Monitoring and traceability

The platform includes availability monitoring and activity logging mechanisms to support tracking, analysis and detection of unusual events.

Hosting & sovereignty

Canadian infrastructure for your data.

CORO uses hosting infrastructure located in Canada. This approach is intended to reduce cross-border transfer concerns and support Canadian organizations’ expectations regarding data location and control.

Infrastructure characteristics may evolve with the platform. Current technical details can be provided to IT teams as part of a security assessment.

Infrastructure

Toronto, Canada

Primary hosting location for platform data and services.

Provider

DigitalOcean

Cloud infrastructure provider used to operate CORO.

Provider framework

SOC 2 Type II

Infrastructure provider certification; this is distinct from CORO itself.

Access & authentication

Restrict access to what is necessary.

Data protection starts with disciplined identity and permission management. CORO structures access according to each user’s responsibilities.

  • Differentiated roles and permissions based on responsibilities.
  • Isolation between customer organizations.
  • Protection against abusive authentication attempts.
  • Logging of user actions.
  • MFA planned for environments and plans requiring enhanced security.
Backup & continuity

Preserve data integrity and availability.

CORO infrastructure includes backup and recovery mechanisms designed to reduce the impact of a technical failure or incident.

Automated backups

Every 6 hours

Regular database backups.

Retention

30 days

Backup retention under the current configuration.

Snapshots

Daily

Infrastructure snapshots supporting recovery scenarios.

Infrastructure availability

99.9%

Published infrastructure-provider SLA for applicable services.

Environment protection

Reduce the exposed surface.

Network firewall

Network access is limited to the services required to operate the platform.

Authentication protection

Mechanisms are applied to protect against repeated and abusive login attempts.

HTTP security headers

Web configuration includes security headers intended to reduce several common classes of risk.

Availability monitoring

Service availability is monitored to help detect interruptions quickly.

Privacy & compliance

An approach aligned with Canadian obligations.

CORO processes personal information under applicable legislation and maintains protection, retention and incident-management practices appropriate to its activities.

Law 25

Quebec personal information protection

PIPEDA

Canadian federal framework where applicable

Canada hosting

Canadian location of platform data

For IT teams

Need to go deeper in your assessment?

Organizations evaluating CORO can request additional technical information regarding architecture, hosting, backups, access and available security controls.

Request technical documentation
  • Architecture and hosting environment
  • Identity and access management
  • Backups and continuity
  • Network protection measures
  • Logging and monitoring
  • Vendor security questionnaire

Security should be verifiable, not merely claimed.

Tell us about your IT, data-protection or compliance requirements. We will walk you through the CORO environment and the controls relevant to your organization.

Request a demo Contact us