Skip to main content

Early customers: free onboarding with a 12-month plan. Save up to A$2,475.

Contact
Enterprise pack

Corexa enterprise · Version 2026-08-14.v1

Corexa Enterprise Security Schedule

Baseline technical and organisational security controls for enterprise contracting and due diligence.

Template only. This document does not become a binding customer-specific agreement merely because it is displayed in Corexa. It applies only when incorporated into a signed order form, enterprise agreement or other written agreement between Corexa and the customer.

1. Security governance

  • Corexa maintains documented privacy, breach-response, access/correction and subprocessor-review workflows for platform operations.
  • Security controls are reviewed as the product, risk profile, hosting architecture and applicable law change.
  • Material incidents are handled through the Corexa compliance incident register with ownership, assessment, containment and remediation records.

2. Identity and access

  • Role-based SiteGrid and business access controls are applied to server and database operations.
  • Row Level Security and server-side authorisation are used for tenant-scoped data where supported by the relevant data model.
  • Enterprise controls include MFA policy support, approved-domain governance, SAML SSO and SCIM provisioning/deprovisioning where configured.
  • SCIM bearer secrets are stored as hashes; displayed tokens are intended to be shown only at creation/rotation.
  • Administrative actions for enterprise security settings are recorded in the SiteGrid audit trail.

3. Application and API security

  • Sensitive platform actions use authenticated server routes and scope checks rather than relying only on hidden client controls.
  • High-risk compliance registers are server-managed and are not exposed through broad direct-client policies.
  • Canonical identity matching is separated from cross-organisation access authority; a match alone is not treated as permission to read another organisation's shared operational history.
  • API/integration credentials and signing secrets must be treated as confidential and rotated if exposure is suspected.

4. Transport, hosting and stored information

Production web and API traffic is intended to use HTTPS/TLS. Corexa relies on its contracted cloud/database/storage providers for relevant infrastructure safeguards, including provider-level controls for stored information where included in the subscribed service. Exact provider, region, processing-location and DPA status is maintained in Corexa's subprocessor register rather than hard-coded into this schedule.

5. Logging and accountability

  • Corexa maintains audit/event records for key SiteGrid administrative and compliance actions.
  • Privacy requests, data-breach assessments, marketing suppression/consent and marketplace safety operations use dedicated controlled workflows.
  • Location sharing is session-limited and requires a current user-facing precise-location notice before a new live customer tracking session can be created.

6. Secure development and change control

  • Schema changes are delivered through versioned migrations and material server/client changes are subject to repository validation appropriate to the change.
  • Corexa uses targeted audit scripts for high-risk invariants such as canonical identity writes, legal account creation and compliance operations.
  • Production fixes should preserve unrelated application logic and avoid weakening row-level security, tenant boundaries or auditability.

7. Business continuity and availability

Corexa uses managed infrastructure and service-provider resilience appropriate to its deployed architecture. Backup, recovery, redundancy and restoration commitments are limited to the capabilities actually enabled in the production service and any additional commitments expressly stated in the executed order form or Service Level Schedule; this schedule does not promise a recovery point, recovery time or certification that has not been expressly agreed.

8. Customer responsibilities

  • Maintain accurate authorised users, roles and access groups and promptly deactivate users who no longer require access.
  • Protect SSO, SCIM, API and administrator credentials and notify Corexa promptly of suspected compromise.
  • Configure workforce/location features lawfully and provide required employee notices, consultation and policies.
  • Do not upload unnecessary sensitive data or use internal/shared fields contrary to their stated visibility.