Security

How AuditProCore protects tenant data, who has access, and how to report vulnerabilities.

SOC 2 Type II
ISO/IEC 27001:2022
Last attestation: 2026-Q1

Encryption

TLS 1.3 in transit; AES-256 at rest. Per-tenant data-encryption keys stored in Azure Key Vault with HSM backing.

Tenant isolation

Every query is filtered by TenantId at the EF Core query-filter layer. Soft-deletion is honoured at the same layer. No cross-tenant queries are physically possible.

Authentication

Email + password with PBKDF2 password hashing; MFA enforced for elevated roles. Session tokens are short-lived (15 min) with refresh-token rotation.

Audit trail

Every mutation captures CreatedAt, CreatedBy, LastModifiedAt, LastModifiedBy, and a row-version stamp. AGSA-grade immutable event triggers protect AGSA-checklist sign-offs.

Hosting

Production runs on Microsoft Azure in the South Africa North region. Backups replicate to South Africa West with a 4-hour RPO and 4-hour RTO. No tenant data leaves South Africa unless the tenant has signed a cross-border-transfer addendum.

Penetration testing

Independent penetration tests are commissioned annually with a CREST-registered firm. The most recent report (2026-01) found zero critical and one high-severity issue, which has been remediated. Letters of attestation are available under NDA on request.

Responsible disclosure

We welcome vulnerability reports from security researchers. Email security@auditprocore.co.za with a description of the issue, reproduction steps, and your disclosure timeline. We acknowledge within 24 hours, fix critical issues within 7 days, and credit researchers in our hall of fame on request. We do not pursue legal action against good-faith researchers.

Active incident?

For incidents in progress (active data exfiltration, account compromise, ransomware indicators), call our 24/7 security hotline on +27 (0)21 555 0911. Do not use email for time-critical incidents.