Security Overview
CoreConverge is designed to protect Customer data using layered technical and operational controls.
Encryption and hosting
CoreConverge uses HTTPS for data in transit. Primary backend compute is deployed in Google Cloud’s `australia-southeast1` region. Credentials and connected-service tokens are stored through encrypted secret-storage mechanisms rather than in application records.
Access and isolation
The platform uses OAuth 2.0 for connected services such as Xero. Customer records are scoped to tenants and database row-level security is used to enforce tenant isolation. Personnel access is limited to the access needed to operate and support the service.
Connected services and AI
Connections to third-party systems are initiated by the Customer. CoreConverge uses approval controls for material customer-facing or external actions. AI-generated outputs are advisory and are subject to human review before a material action is taken.
Monitoring and response
CoreConverge uses logging and error monitoring to detect reliability and security issues. If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
For current processing providers, see our sub-processor list.
Contact
kalyan@coreconverge.com.au