Security & Trust
1. Our Commitment
RegulaCore Inc. is built for teams that manage sensitive EHS, quality, and compliance records. This page distinguishes implemented controls, provider capabilities, and roadmap items so buyers can evaluate our current posture without relying on ambiguous badges.
2. Assurance and Compliance Status
SOC 2
No SOC 2 Type II report is currently represented as issued. Controls and evidence are being organized against the Trust Services Criteria in preparation for independent readiness review.
ISO/IEC 27001
RegulaCore is not currently represented as ISO/IEC 27001 certified. Information-security governance and control mapping are being documented against the 2022 standard.
Data Protection
Our DPA describes processing commitments, subprocessors, security measures, and support for applicable GDPR, UK GDPR, and U.S. privacy obligations.
HIPAA-regulated use
No HIPAA certification is claimed. Prospective deployments involving protected health information require a written security review and an approved BAA before use.
3. Procurement Documents
These materials are available for self-service review. Requests for countersigned agreements or non-public evidence are handled directly by our security and privacy teams.
Request procurement documents
Send the request securely in your browser. RegulaCore will use these details only to evaluate and fulfill your procurement request.
Our security team will respond within 1 business day.
4. Infrastructure Security
4.1 Edge Security & Cloud Infrastructure
RegulaCore's inspected production architecture is Cloudflare-native. Application services run on Cloudflare Workers, with managed Cloudflare services providing relational data, object storage, configuration storage, and stateful coordination.
- Cloudflare Workers provide edge application compute.
- Cloudflare D1 stores relational application data in a shared multi-tenant data model.
- Cloudflare R2 stores tenant-namespaced objects and uploaded evidence.
- Cloudflare KV stores selected configuration, cache, and session-support data.
- Cloudflare Durable Objects provide strongly coordinated state for selected platform services.
4.2 Network and Browser Security
- HTTPS is enforced at Cloudflare's edge; supported clients negotiate modern TLS.
- Cloudflare provides network-layer DDoS protection. WAF rules and other account controls are reviewed as deployment configuration, not inferred from the hosting provider alone.
- Marketing responses are configured with HSTS, anti-framing, MIME-sniffing protection, a restrictive referrer policy, and a permissions policy.
- The Security & Trust page is protected by an enforced Content Security Policy. A report-only policy is used to safely harden remaining legacy marketing pages without breaking customer workflows.
5. Data Security
5.1 Encryption
| Layer | Standard |
|---|---|
| Data in transit | HTTPS through Cloudflare's edge |
| D1 data at rest | AES-256 encryption provided by Cloudflare |
| R2 objects at rest | AES-256 encryption provided by Cloudflare |
| Tenant separation | Authenticated tenant context plus tenant-scoped queries and object namespaces |
5.2 Tenant Isolation
RegulaCore uses a shared multi-tenant data model. Tenant isolation is enforced in the application and authorization layers:
- Tenant-owned records include a tenant identifier and queries are scoped to the authenticated tenant context.
- Protected API requests require a verified tenant or administrator session before tenant data is returned.
- File-storage keys are namespaced by tenant and authorization is evaluated before access.
- Tenant-isolation regression tests and endpoint authorization reviews are part of the security hardening program.
5.3 Access Controls
- Role-Based Access Control (RBAC): Granular permissions at the module, feature, and data level.
- Session protection: Signed, expiring session tokens are carried in secure HTTP-only cookies where supported.
- Multi-Factor Authentication: Account and tenant policy capabilities are disclosed during solution review; buyers should confirm the controls required for their deployment.
- Enterprise identity: SSO/provider availability is confirmed in the applicable order form rather than assumed from a generic compatibility claim.
6. Application Security
6.1 Secure Development
- Authentication secrets are required deployment bindings; production code does not fall back to predictable development secrets.
- Protected endpoint behavior is reviewed for missing authentication and tenant scope.
- D1 queries use parameter binding for customer-controlled values.
- Dependency review, static analysis, and authorization regression coverage are tracked controls; evidence is provided only after the applicable automation is operating.
6.2 Independent Testing
Independent penetration-test reports are not represented as available until an assessment has been completed. When issued, an executive summary and remediation status will be made available to qualified customers under NDA.
6.3 Vulnerability Management
Security reports are triaged according to severity and exploitability. Remediation commitments are established in customer agreements only when supported by an approved operational policy and measured evidence.
7. Audit Logging
RegulaCore records tenant-scoped operational and audit events for supported workflows, which may include:
- User authentication events (login, logout, MFA, failed attempts).
- Data access and modification events with before/after snapshots.
- Administrative actions (user management, role changes, settings modifications).
- API access logs with request metadata.
Retention depends on the applicable product configuration and customer agreement. RegulaCore does not describe current D1 audit records as immutable or tamper-proof. Append-only and tamper-evidence controls remain part of the assurance roadmap.
8. Business Continuity and Recovery
- Cloudflare provides distributed edge infrastructure for the application and managed storage services.
- D1 recovery capabilities depend on the active Cloudflare plan and database version and are verified before contractual recovery commitments are made.
- Customer-specific availability, retention, RTO, and RPO commitments appear in the applicable service agreement, not as unsupported universal promises.
- Restore exercises and incident-response tests are maintained as evidence-producing assurance activities.
9. Incident Response
RegulaCore's incident-response process is designed to cover:
- Detection: Automated monitoring and alerting for anomalous activity.
- Triage: Classification by severity level with defined escalation paths.
- Notification: Customer notification without undue delay as required by applicable law and the DPA.
- Remediation: Root cause analysis and corrective actions for every incident.
- Post-Incident Review: Lessons learned documented and shared with affected customers.
10. Responsible Disclosure
We value the security research community. If you discover a security vulnerability, please report it responsibly:
- Email: support@regulacore.com
- Include a detailed description, reproduction steps, and your contact information.
- We aim to acknowledge receipt within two business days and will coordinate remediation based on severity.
- We do not pursue legal action against researchers who follow responsible disclosure principles.
11. Subprocessors
The current list of subprocessors and their purposes is maintained in our Data Processing Addendum. Questions or objections may be sent to support@regulacore.com.
12. Contact
For security inquiries, audit requests, or to report a vulnerability:
RegulaCore Inc.
500 Navarro St, 2nd Floor, PMB 7096
San Antonio, TX 78205
United States
Security and privacy support: support@regulacore.com