Trust Center
Trust, documented.
Security, privacy, and compliance documentation for Corvalon HRM.
Corvalon HRM protects customer data with defense-in-depth security: tenant isolation, field-level encryption, least-privilege access, and a tamper-evident audit trail. The documents below let your security team evaluate our platform without a call. All documents are also available under NDA along with an architecture review.
Compliance status
SOC 2 Type II: in preparation. The observation window has not yet started, and no SOC 2 report exists today. We make no claim of SOC 2 certification. In the interim, we publish this controls mapping and completed CAIQ-Lite and SIG-Lite self-assessments so security reviews are not blocked while the examination is in progress.
Corvalon HRM is designed to meet SOC 2, GDPR, CCPA/CPRA, US state privacy laws, and WCAG 2.1 AA / Section 508. Self-assessments are vendor attestations, not independent audit opinions.
Security highlights
- Tenant isolation: Dedicated PostgreSQL schema per customer plus row-level security.
- Field-level encryption: SSN, bank, and EIN encrypted via Vault Transit with per-tenant keys.
- MFA: TOTP and WebAuthn/FIDO2, required for all administrative roles.
- Tamper-evident audit trail: Append-only, hash-chained, 7-year retention, verified daily.
- Continuous scanning: SAST, DAST, dependency, and container scans on every change.
- SSO and SCIM: OIDC and SAML sign-in with SCIM 2.0 user provisioning.
Security & Compliance
Our security architecture, controls mapping, and completed self-assessment questionnaires.
Security Overview
A public overview of our security architecture, authentication, encryption, tenant isolation, and vulnerability management.
Download Security Overview (Markdown)SOC 2 Controls Mapping
Platform controls mapped to the SOC 2 Trust Service Criteria across Security, Availability, Confidentiality, Processing Integrity, and Privacy.
Download SOC 2 Controls Mapping (Markdown)CAIQ-Lite Self-Assessment
Completed Cloud Security Alliance CAIQ-Lite questionnaire (CCM v4) for security reviews.
Download CAIQ-Lite Self-Assessment (Markdown)SIG-Lite Self-Assessment
Completed Shared Assessments SIG-Lite questionnaire covering the standard risk-control domains.
Download SIG-Lite Self-Assessment (Markdown)Change Management Policy
Our authorize, test, approve, and deploy workflow, including compensating controls for a small-team vendor.
Download Change Management Policy (Markdown)Vulnerability Disclosure Policy
How to report a security issue and the safe-harbor protections we provide to researchers.
Download Vulnerability Disclosure Policy (Markdown)
Privacy & Data Protection
How we handle personal data, our processing agreement, and the sub-processors we rely on.
Privacy Practices
How we collect, use, retain, and protect personal data, and how data subjects exercise their rights.
Download Privacy Practices (Markdown)Data Processing Agreement (Template)
Our standard DPA covering processing terms, security measures, and sub-processor obligations.
Download Data Processing Agreement (Template) (Markdown)Sub-Processor List
The current list of sub-processors, the data each handles, and our 30-day change-notification commitment.
Download Sub-Processor List (Markdown)
International Data Transfers
Contractual mechanisms and assessments supporting cross-border data transfers.
Standard Contractual Clauses
EU Standard Contractual Clauses supporting transfers of personal data outside the EEA.
Download Standard Contractual Clauses (Markdown)Transfer Impact Assessment
Our assessment of the legal and practical protections for personal data transferred internationally.
Download Transfer Impact Assessment (Markdown)UK International Data Transfer Addendum
The UK IDTA addendum to the SCCs for transfers of UK personal data.
Download UK International Data Transfer Addendum (Markdown)
Accessibility
Our conformance with WCAG 2.1 AA and Section 508.
Accessibility Conformance Report (VPAT)
Our Voluntary Product Accessibility Template documenting WCAG 2.1 AA and Section 508 conformance.
Download Accessibility Conformance Report (VPAT) (Markdown)
Contact
Security reports and questionnaires: security@corvalonhrm.com. Compliance and privacy: compliance@corvalonhrm.com.