Security & Trust

1. Our Commitment

RegulaCore Inc. ("RegulaCore Inc") is built for enterprise teams that manage sensitive EHS, quality, and compliance data. Security is foundational to everything we build — not an afterthought. This page provides transparency into our security architecture, certifications, and data protection practices.

2. Certifications and Compliance

SOC 2 Type II

Annual audit covering security, availability, and confidentiality trust service criteria.

ISO 27001 Aligned

Information security management system aligned to ISO/IEC 27001:2022 controls.

GDPR

Full compliance with EU and UK General Data Protection Regulations. DPA available on request.

HIPAA

Business Associate Agreement (BAA) available for customers handling protected health information.

3. Infrastructure Security

3.1 Cloud Architecture

RegulaCore Inc runs entirely on Cloudflare's global edge network — there is no traditional origin server. This architecture provides:

3.2 Network Security

4. Data Security

4.1 Encryption

LayerStandard
Data in transitTLS 1.3 with forward secrecy
Data at restAES-256 encryption
Database connectionsEncrypted connections with per-tenant isolation
BackupsAES-256 encrypted, stored in geographically distributed locations

4.2 Tenant Isolation

RegulaCore Inc uses a zero-trust, multi-tenant architecture where:

4.3 Access Controls

5. Application Security

5.1 Secure Development

5.2 Penetration Testing

We conduct regular penetration testing through qualified third-party firms. Findings are remediated on a risk-prioritized basis. Executive summaries are available to enterprise customers under NDA.

5.3 Vulnerability Management

We monitor the Common Vulnerabilities and Exposures (CVE) database and security advisories for all dependencies. Critical vulnerabilities are patched within 24 hours; high-severity issues within 72 hours.

6. Audit Logging

RegulaCore Inc maintains comprehensive audit logs for every tenant, including:

Audit logs are immutable, timestamped, and retained for a minimum of 7 years to support regulatory compliance requirements for EHS and ISO programs.

7. Business Continuity and Disaster Recovery

8. Incident Response

RegulaCore Inc maintains a documented incident response plan that includes:

9. Responsible Disclosure

We value the security research community. If you discover a security vulnerability, please report it responsibly:

10. Sub-processors

A current list of sub-processors is maintained in our Data Processing Addendum. We notify customers 30 days before engaging new sub-processors.

11. Contact

For security inquiries, audit requests, or to report a vulnerability:

RegulaCore Inc.
500 Navarro St, 2nd Floor, PMB 7096
San Antonio, TX 78205
United States

Security team: security@regulacore.com
Privacy team: privacy@regulacore.com