Engineeredforsecurity. Designed for due diligence.
Everything an advisor IT or procurement team needs to clear Core Growth AI through their vendor-risk process — SOC 2 status, encryption posture, US data residency, full subprocessor list, and a packet your CCO can route internally in one email.
Six controls every CCO procurement form asks about.
We surface the status honestly — including what's done, what's in progress, and what's on the audit roadmap. Generic claims fail procurement; specificity earns approvals.
SOC 2 Type II
Control framework selected, evidence collection underway. We don't publish a Type II claim until the report is in hand. Roadmap update + auditor name share-able under NDA.
Encryption
All API traffic terminates over TLS. Database storage is encrypted at rest by our cloud provider (managed Postgres + object storage). Secrets stored in a managed vault, never in source.
US data residency
Production database, object storage, and application servers run in US-only AWS regions via Supabase + Vercel. No data leaves the United States in normal operation.
Identity + access
Customer authentication runs through Clerk. SSO available on Enterprise (SAML 2.0, Okta, Entra ID). Role-based access controls (RBAC) scoped to org_id at the row level.
Monitoring + incident response
Application and infrastructure logs centralized for retention and alerting. On-call rotation with documented severity tiers and customer-notification SLA for any incident affecting confidentiality or availability.
Penetration testing
Independent third-party penetration testing committed to as part of SOC 2 program. First scheduled test window and remediation tracking will be shared in the compliance packet.
Every third party that touches your data, named.
Public list with purpose and data scope. Customer-connected integrations (CRMs) are gated — they only see data once the customer grants OAuth access from inside the product.
| Vendor | Purpose | Data scope | Region |
|---|---|---|---|
| Amazon Web Services | Underlying cloud infrastructure (compute, storage) | All operational data | United States |
| Supabase | Managed Postgres database + storage + auth backend | Lead records, dossiers, advisor metadata, audit logs | United States |
| Vercel | Application + marketing-site hosting + edge runtime | Application code + static assets (no PII) | United States |
| Clerk | Customer authentication + SSO (SAML, Okta, Entra) | Advisor identity, session tokens | United States |
| Anthropic (Claude) | AI dossier generation + outreach drafting | Public-record context (names, titles, SEC-filing references) | United States |
| Exa | Public news + biographical research enrichment | Names + companies for web-research queries | United States |
| Apollo | B2B contact-information enrichment | Names + companies for contact lookup | United States |
| Prospeo | Email-deliverability verification | Email addresses for syntax + MX verification | United States |
| Resend | Transactional email delivery (marketing-site + alerts) | Customer email addresses + outbound message bodies | United States |
| WealthboxCustomer-gated | Customer CRM integration — only when customer connects it | Customer's own CRM contacts (read + write, scoped via OAuth) | United States |
| Salesforce Financial Services CloudCustomer-gated | Customer CRM integration — only when customer connects it | Customer's own CRM contacts (read + write, scoped via OAuth) | United States |
List re-verified quarterly. Material changes are emailed to customer security contacts at least 30 days in advance.
Insurance & coverage
- ·Tech E&O / Cyber liability · [CONFIRM: carrier · $X aggregate / $Y per claim]
- ·General liability · [CONFIRM: carrier · limits]
- ·Certificate of insurance available on request, shareable before contract execution.
Incident response
- ·Documented severity tiers (P0–P3) with owner + escalation paths.
- ·Customer-notification SLA for any incident affecting confidentiality, integrity, or availability of customer data.
- ·Post-incident report shared with affected customers within 10 business days, including root cause + remediation.
- ·Security contact: security@coregrowthai.com
Data-handling principles
One email. Everything your CCO needs.
Share a few details and we'll send a single PDF bundle your compliance or procurement lead can route internally without another round trip.
- ·Security overview (controls + roadmap)
- ·SOC 2 status + auditor (NDA)
- ·Due-diligence questionnaire (CAIQ-lite format)
- ·Data-handling overview + retention policy
- ·Subprocessor list with data-scope detail
- ·Insurance certificate (E&O + cyber)
- ·Regulatory-framework alignment (SEC Marketing Rule, GLBA)
- ·Incident-response runbook summary
Or email security@coregrowthai.com directly.