This is an info Alert.
  • Home
  • Customers
  • Team
  • Careers
  • Training
  • Security
  • Contact
Sign in
TRUST CENTER

Security is how we build,
not a feature we added

CoresPro handles the commercial heart of your business: proposals, rates, margins, and delivery data. Here is exactly how we protect it.
AICPA SOC for Service Organizations badge
SOC 2 Type I
Independent service auditor's report
July 7, 2026
Security · Availability · Confidentiality
HOW WE PROTECT YOUR DATA

Controls that are architecture, not policy documents

Encryption everywhere

All traffic is HTTPS with managed TLS - there is no unencrypted path into the platform. Data is encrypted at rest in Google Cloud SQL and Cloud Storage.

Tenant isolation by design

Every customer's data lives in its own database schema. Isolation is enforced at the application layer on every request, before any data is loaded.

Least-privilege access

Role-based access control down to individual objects and operations, with an audit log on every change. The database accepts no public connections - access is IAM-authenticated and mutually verified (mTLS).

Peer-reviewed changes

No code reaches production without an independent review: the author of a change can never be its approver. Every deploy is automated, versioned, and reversible.

Hardened cloud infrastructure

CoresPro runs entirely on managed infrastructure from Google Cloud and Vercel - no self-managed servers, no open inbound ports, automatic patching at the platform layer.

Continuous monitoring

Compliance controls are monitored continuously through an automated platform, with alerts on drift - not checked once a year.

COMPLIANCE

Where we are and where we're going

July 2026
SOC 2 Type I

An independent auditor examined the design of our security, availability, and confidentiality controls and issued an unqualified report.

Next
SOC 2 Type II

Our next milestone: verifying that the same controls operate effectively over an extended observation period.

Want the details?

Our SOC 2 report is available to customers and prospects under NDA. We're happy to walk your security team through our architecture.


Professional services management platform. Proposals, scheduling, delivery, time and expense, and reporting.

AICPA SOC for Service Organizations badgeSOC 2 Type I attestedSecurity · Availability · Confidentiality
Product
CustomersTrainingSecurityFAQs
Company
About usTeamCareersContact us
Legal
Terms of servicePrivacy policy

© All rights reserved.