Skip to main content

Trust Center

Trust, documented.

Security, privacy, and compliance documentation for Corvalon HRM.

Corvalon HRM protects customer data with defense-in-depth security: tenant isolation, field-level encryption, least-privilege access, and a tamper-evident audit trail. The documents below let your security team evaluate our platform without a call. All documents are also available under NDA along with an architecture review.

Compliance status

SOC 2 Type II: in preparation. The observation window has not yet started, and no SOC 2 report exists today. We make no claim of SOC 2 certification. In the interim, we publish this controls mapping and completed CAIQ-Lite and SIG-Lite self-assessments so security reviews are not blocked while the examination is in progress.

Corvalon HRM is designed to meet SOC 2, GDPR, CCPA/CPRA, US state privacy laws, and WCAG 2.1 AA / Section 508. Self-assessments are vendor attestations, not independent audit opinions.

Security highlights

  • Tenant isolation: Dedicated PostgreSQL schema per customer plus row-level security.
  • Field-level encryption: SSN, bank, and EIN encrypted via Vault Transit with per-tenant keys.
  • MFA: TOTP and WebAuthn/FIDO2, required for all administrative roles.
  • Tamper-evident audit trail: Append-only, hash-chained, 7-year retention, verified daily.
  • Continuous scanning: SAST, DAST, dependency, and container scans on every change.
  • SSO and SCIM: OIDC and SAML sign-in with SCIM 2.0 user provisioning.

Security & Compliance

Our security architecture, controls mapping, and completed self-assessment questionnaires.

Privacy & Data Protection

How we handle personal data, our processing agreement, and the sub-processors we rely on.

International Data Transfers

Contractual mechanisms and assessments supporting cross-border data transfers.

Accessibility

Our conformance with WCAG 2.1 AA and Section 508.

Contact

Security reports and questionnaires: security@corvalonhrm.com. Compliance and privacy: compliance@corvalonhrm.com.