Skip to content
See Corei on your own data in a 45–60 minute demo.
Corei
Security & Trust

Built for the people who already protect everyone else.

MSPs sit at the center of their customers' security. Corei is built around that reality — with strict tenant isolation, least-privilege access, encryption in transit and at rest, and AI controls that respect what your customers consider private.

This page is maintained by Corei and describes current product practices. It is not an independent certification or audit report; we'll publish formal attestation status as it becomes available.

Tenant: Stonebridge MSP

Security posture · live

Healthy

SSO

Entra ID

MFA

Required

Encryption

AES-256 / TLS 1.3

Recent audit events

Role granted: Service Lead · by admin@stonebridge
Corei action: quote draft for Cobalt Tooling · logged
Customer scope: Halcyon Health · PHI fields masked
API key rotated · ConnectWise PSA · success

Corei · Governance

3 actions today required approval (quotes > $25k). All grounded in tenant-scoped data only — no cross-customer training.

Pillars

Four pillars our security program is organized around.

We design for the security-first MSP buyer. Every feature is evaluated against these principles before it ships.

Tenant isolation

Every MSP — and every customer underneath them — has its own logical boundary. Queries, AI context, and writes never cross tenants.

Least-privilege access

Role-based and customer-scoped permissions throughout. People and AI agents only see what their role and scope allow.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Secrets stored in a managed vault and rotated on a schedule.

Transparent operations

Full audit trails for human and AI actions. You can see what was done, by whom, on which record, with what reasoning.

Data protection

Your customer data stays yours — and stays separated.

Corei stores MSP business data — tickets, projects, accounts, quotes, devices, and the relationships between them. We treat it the way a serious MSP treats its own customers' data.

  • AES-256 encryption at rest; TLS 1.3 in transit
  • Logical tenant isolation enforced at the database and API layers
  • Customer-scope tags on records so AI and humans cannot leak across customers
  • Secrets and API keys held in a managed vault with rotation
  • Backups encrypted, restorable, and tested on a regular cadence
  • Hosted on a major cloud provider with regional data residency on request

Data flow · single record

Step 1 · Edge (TLS 1.3)

Request authenticated · SSO claims verified

Step 2 · API

Tenant + role scope evaluated · request signed

Step 3 · Database

Row-level tenancy · AES-256 at rest

Step 4 · Audit log

Actor, action, record, reasoning — immutable

Identity & access

The right people see the right things — and nothing else.

Corei assumes a multi-role MSP: technicians, dispatchers, account managers, project managers, and leadership. Permissions are scoped to role and to the customers each person serves.

SSO via Entra ID / Google Workspace

Standards-based OIDC and SAML. Provision and deprovision in your identity provider — Corei honors it.

MFA enforced

MFA required for all human access by default. Configurable session policies and idle timeouts.

Role-based access control

Granular roles for service, dispatch, sales, projects, and admin — plus custom roles for your operating model.

Customer-scope permissions

Per-user customer scope so a technician sees the customers they actually serve — not your entire book.

Full audit trail

Every login, role change, and record write is logged with actor, timestamp, and source IP.

Sensitive-action approvals

Quotes above a threshold, role grants, and customer-data exports can require a second approver.

IP restrictions

Allowlist trusted office, VPN, or CIDR ranges. Requests from unapproved networks are blocked before login.

Conditional access policies

Context-aware rules — device posture, location, network, and time-of-day — gate sign-in and elevate risk-based step-up MFA.

AI governance

Corei is governed the same way your best technician is.

Corei is the AI layer inside Corei. It runs under the same role and scope as the person who invokes it, only reads tenant-scoped data, and is logged like any other actor on the platform.

  • Your tenant data is not used to train shared or third-party foundation models
  • Cross-customer context is off by default; opt-in clustering is anonymized
  • Every AI write action is logged with prompt, sources, and reasoning
  • Admin controls define which AI actions are autonomous, suggested, or require approval
  • PII and sensitive fields can be masked from AI prompts on a per-customer basis

Corei permission policy

Read tickets, devices, accounts

Autonomous

Draft customer-facing replies

Suggest only

Approve quotes ≤ $25,000

Autonomous

Approve quotes > $25,000

Requires human

Grant or change user roles

Blocked

Export customer data

Requires human

Policies are defined by your admin. Every Corei action carries its policy decision into the audit log.

Operations & incident response

We run the platform the way a mature MSP runs its NOC.

Secure SDLC

Peer-reviewed code, automated dependency scanning, and CI checks gate every release.

Vulnerability management

Continuous dependency and infrastructure scanning. Critical fixes are prioritized and tracked.

Monitoring & alerting

24/7 platform monitoring with on-call escalation. Customer-impacting incidents are flagged automatically.

Incident response

Documented IR runbook. Affected customers are notified directly when their data or service is impacted.

Compliance roadmap

Where we are, and where we're going.

We're transparent about what's in place today versus what's on the roadmap. Ask us for the latest status under NDA — we'd rather share details than make claims.

In place
  • SOC 2-aligned controls
  • Encryption at rest & in transit
  • SSO & MFA enforcement
  • Tenant isolation
In progress
  • SOC 2 Type II attestation
  • Penetration test (annual)
  • Sub-processor disclosure portal
On the roadmap
  • HIPAA-aligned BAAs (where applicable)
  • Regional data residency expansion
  • Customer-managed encryption keys

Compliance items reflect Corei's current program. Statuses change as audits complete; contact us for the most recent letter, scoping memo, or sub-processor list before signing.

Doing security diligence on Corei?

Reach out to our security team for our SOC 2 alignment overview, sub-processor list, architecture overview, or to coordinate a penetration-test window. Vulnerability reports are reviewed and acknowledged within one business day.

SOC 2-aligned controls
SSO + MFA enforced by default
Full audit trail — human + AI