Built for the people who already protect everyone else.
MSPs sit at the center of their customers' security. Corei is built around that reality — with strict tenant isolation, least-privilege access, encryption in transit and at rest, and AI controls that respect what your customers consider private.
This page is maintained by Corei and describes current product practices. It is not an independent certification or audit report; we'll publish formal attestation status as it becomes available.
Tenant: Stonebridge MSP
Security posture · live
SSO
Entra ID
MFA
Required
Encryption
AES-256 / TLS 1.3
Recent audit events
Corei · Governance
3 actions today required approval (quotes > $25k). All grounded in tenant-scoped data only — no cross-customer training.
Four pillars our security program is organized around.
We design for the security-first MSP buyer. Every feature is evaluated against these principles before it ships.
Tenant isolation
Every MSP — and every customer underneath them — has its own logical boundary. Queries, AI context, and writes never cross tenants.
Least-privilege access
Role-based and customer-scoped permissions throughout. People and AI agents only see what their role and scope allow.
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Secrets stored in a managed vault and rotated on a schedule.
Transparent operations
Full audit trails for human and AI actions. You can see what was done, by whom, on which record, with what reasoning.
Your customer data stays yours — and stays separated.
Corei stores MSP business data — tickets, projects, accounts, quotes, devices, and the relationships between them. We treat it the way a serious MSP treats its own customers' data.
- AES-256 encryption at rest; TLS 1.3 in transit
- Logical tenant isolation enforced at the database and API layers
- Customer-scope tags on records so AI and humans cannot leak across customers
- Secrets and API keys held in a managed vault with rotation
- Backups encrypted, restorable, and tested on a regular cadence
- Hosted on a major cloud provider with regional data residency on request
Data flow · single record
Step 1 · Edge (TLS 1.3)
Request authenticated · SSO claims verified
Step 2 · API
Tenant + role scope evaluated · request signed
Step 3 · Database
Row-level tenancy · AES-256 at rest
Step 4 · Audit log
Actor, action, record, reasoning — immutable
The right people see the right things — and nothing else.
Corei assumes a multi-role MSP: technicians, dispatchers, account managers, project managers, and leadership. Permissions are scoped to role and to the customers each person serves.
SSO via Entra ID / Google Workspace
Standards-based OIDC and SAML. Provision and deprovision in your identity provider — Corei honors it.
MFA enforced
MFA required for all human access by default. Configurable session policies and idle timeouts.
Role-based access control
Granular roles for service, dispatch, sales, projects, and admin — plus custom roles for your operating model.
Customer-scope permissions
Per-user customer scope so a technician sees the customers they actually serve — not your entire book.
Full audit trail
Every login, role change, and record write is logged with actor, timestamp, and source IP.
Sensitive-action approvals
Quotes above a threshold, role grants, and customer-data exports can require a second approver.
IP restrictions
Allowlist trusted office, VPN, or CIDR ranges. Requests from unapproved networks are blocked before login.
Conditional access policies
Context-aware rules — device posture, location, network, and time-of-day — gate sign-in and elevate risk-based step-up MFA.
Corei is governed the same way your best technician is.
Corei is the AI layer inside Corei. It runs under the same role and scope as the person who invokes it, only reads tenant-scoped data, and is logged like any other actor on the platform.
- Your tenant data is not used to train shared or third-party foundation models
- Cross-customer context is off by default; opt-in clustering is anonymized
- Every AI write action is logged with prompt, sources, and reasoning
- Admin controls define which AI actions are autonomous, suggested, or require approval
- PII and sensitive fields can be masked from AI prompts on a per-customer basis
Corei permission policy
Read tickets, devices, accounts
AutonomousDraft customer-facing replies
Suggest onlyApprove quotes ≤ $25,000
AutonomousApprove quotes > $25,000
Requires humanGrant or change user roles
BlockedExport customer data
Requires humanPolicies are defined by your admin. Every Corei action carries its policy decision into the audit log.
We run the platform the way a mature MSP runs its NOC.
Secure SDLC
Peer-reviewed code, automated dependency scanning, and CI checks gate every release.
Vulnerability management
Continuous dependency and infrastructure scanning. Critical fixes are prioritized and tracked.
Monitoring & alerting
24/7 platform monitoring with on-call escalation. Customer-impacting incidents are flagged automatically.
Incident response
Documented IR runbook. Affected customers are notified directly when their data or service is impacted.
Where we are, and where we're going.
We're transparent about what's in place today versus what's on the roadmap. Ask us for the latest status under NDA — we'd rather share details than make claims.
- SOC 2-aligned controls
- Encryption at rest & in transit
- SSO & MFA enforcement
- Tenant isolation
- SOC 2 Type II attestation
- Penetration test (annual)
- Sub-processor disclosure portal
- HIPAA-aligned BAAs (where applicable)
- Regional data residency expansion
- Customer-managed encryption keys
Compliance items reflect Corei's current program. Statuses change as audits complete; contact us for the most recent letter, scoping memo, or sub-processor list before signing.
Doing security diligence on Corei?
Reach out to our security team for our SOC 2 alignment overview, sub-processor list, architecture overview, or to coordinate a penetration-test window. Vulnerability reports are reviewed and acknowledged within one business day.
