Security & Trust

1. Our Commitment

RegulaCore Inc. is built for teams that manage sensitive EHS, quality, and compliance records. This page distinguishes implemented controls, provider capabilities, and roadmap items so buyers can evaluate our current posture without relying on ambiguous badges.

Transparency commitment: RegulaCore does not claim a certification or independent audit report unless the corresponding document has been issued and is available for qualified customer review.

2. Assurance and Compliance Status

Readiness roadmap

SOC 2

No SOC 2 Type II report is currently represented as issued. Controls and evidence are being organized against the Trust Services Criteria in preparation for independent readiness review.

Alignment roadmap

ISO/IEC 27001

RegulaCore is not currently represented as ISO/IEC 27001 certified. Information-security governance and control mapping are being documented against the 2022 standard.

Program active

Data Protection

Our DPA describes processing commitments, subprocessors, security measures, and support for applicable GDPR, UK GDPR, and U.S. privacy obligations.

Eligibility review

HIPAA-regulated use

No HIPAA certification is claimed. Prospective deployments involving protected health information require a written security review and an approved BAA before use.

3. Procurement Documents

These materials are available for self-service review. Requests for countersigned agreements or non-public evidence are handled directly by our security and privacy teams.

Download Security Whitepaper Download DPA Request Countersigned DPA Request Security NDA

Request procurement documents

Send the request securely in your browser. RegulaCore will use these details only to evaluate and fulfill your procurement request.

4. Infrastructure Security

4.1 Edge Security & Cloud Infrastructure

RegulaCore's inspected production architecture is Cloudflare-native. Application services run on Cloudflare Workers, with managed Cloudflare services providing relational data, object storage, configuration storage, and stateful coordination.

4.2 Network and Browser Security

5. Data Security

5.1 Encryption

LayerStandard
Data in transitHTTPS through Cloudflare's edge
D1 data at restAES-256 encryption provided by Cloudflare
R2 objects at restAES-256 encryption provided by Cloudflare
Tenant separationAuthenticated tenant context plus tenant-scoped queries and object namespaces

5.2 Tenant Isolation

RegulaCore uses a shared multi-tenant data model. Tenant isolation is enforced in the application and authorization layers:

5.3 Access Controls

6. Application Security

6.1 Secure Development

6.2 Independent Testing

Independent penetration-test reports are not represented as available until an assessment has been completed. When issued, an executive summary and remediation status will be made available to qualified customers under NDA.

6.3 Vulnerability Management

Security reports are triaged according to severity and exploitability. Remediation commitments are established in customer agreements only when supported by an approved operational policy and measured evidence.

7. Audit Logging

RegulaCore records tenant-scoped operational and audit events for supported workflows, which may include:

Retention depends on the applicable product configuration and customer agreement. RegulaCore does not describe current D1 audit records as immutable or tamper-proof. Append-only and tamper-evidence controls remain part of the assurance roadmap.

8. Business Continuity and Recovery

9. Incident Response

RegulaCore's incident-response process is designed to cover:

10. Responsible Disclosure

We value the security research community. If you discover a security vulnerability, please report it responsibly:

11. Subprocessors

The current list of subprocessors and their purposes is maintained in our Data Processing Addendum. Questions or objections may be sent to support@regulacore.com.

12. Contact

For security inquiries, audit requests, or to report a vulnerability:

RegulaCore Inc.
500 Navarro St, 2nd Floor, PMB 7096
San Antonio, TX 78205
United States

Security and privacy support: support@regulacore.com