Security Center
How CORE KSA Technologies protects client data and secures its own operations.
This page is maintained by CORE KSA Technologies to answer common security questions about how we operate. It reflects controls currently in place and is updated as our program evolves.
Security is a shared responsibility between CORE KSA, our clients, and the third-party platforms we integrate with. The information below describes CORE KSA's practices and controls; client-side and platform responsibilities are documented separately in each engagement's Master Service Agreement and shared responsibility matrix.
Access & authentication
- All employee access requires SSO with phishing-resistant multi-factor authentication.
- Privileged access is granted just-in-time via a documented approval workflow.
- All administrative activity is logged and reviewed.
Data protection
- Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Least-privilege access is enforced across all internal systems.
- Data loss prevention (DLP) controls apply to all endpoints.
Monitoring & response
- 24/7 security monitoring by our internal SOC.
- Documented incident response plan with tabletop exercises twice per year.
- Client notification within contractual timeframes for any confirmed incident.
Vulnerability reporting
To responsibly disclose a security concern, email security@coreksatech.example. We commit to acknowledging reports within one business day.
This page describes practices maintained by CORE KSA and does not constitute a third-party certification.