Home / Security Center

Security Center

This page is maintained by CORE KSA Technologies to answer common security and privacy questions about how we operate and protect the environments we manage. It describes our current, in-use controls and is not a certification or third-party attestation.

Access & authentication

  • Role-based access with least-privilege defaults
  • MFA required for all engineers and administrative accounts
  • Just-in-time elevation for privileged actions
  • Session recording for high-impact environments

Data handling

  • Encryption in transit (TLS 1.2+) and at rest for managed systems
  • Documented retention windows aligned to each client's policy
  • Data separation between client tenants and workspaces
  • Signed subprocessor list available on request

Monitoring & response

  • 24/7 alerting for endpoints, identities, and network devices
  • Documented incident response with defined severity tiers
  • Root-cause reviews after every P1/P2 incident
  • Change management with peer review and rollback plans

Vendor & platform posture

  • Preference for platforms with SOC 2 or ISO 27001 attestations
  • Vendor security reviews before integration
  • Regular patching cadence with maintenance windows
  • Backups tested on a scheduled basis

Reporting a vulnerability

Email security@coreksatech.example with reproduction details. We acknowledge reports within one business day and coordinate remediation with the affected client(s).

Shared responsibility

Security is a partnership. CORE KSA operates and monitors the platforms and controls we manage; each client owns policy decisions, data classification, and end-user practices in their environment. Every engagement includes a written responsibility matrix.

For contractual security terms, DPAs, or an updated subprocessor list, contact privacy@coreksatech.example. See also our detailed Security Center and Compliance page.