Features Security Blogs

Solcoro Data Security & Trust

Your data is encrypted, access-controlled, and hosted on AWS. Here's exactly how we protect it.

Our Security Strategy

Your data is only as valuable as it is secure. That's why security, privacy, and reliability aren't features at Solcoro; they're the foundation. We take a defense-in-depth approach, designing every layer of the platform to limit exposure, enforce controls, and surface issues before they become problems.

Minimize Access

Only what is needed, when it is needed. The Solcoro platform receives only the metadata a customer has authorized—delivered securely, and only when needed. Solcoro does not "pull" metadata.

Automate Securely

Every change is defined, reviewed, and deployed via code. All changes are fully logged and follow AWS and Git best practices—no manual changes, no undocumented access.

Monitor Everything

Full observability across the Solcoro platform systems ensures issues are detected early and handled quickly—before they affect customers.

Data Protection & Infrastructure

Data Protection

  • Encryption: All customer data is encrypted in transit (TLS 1.2+) and at rest using industry-standard AES-256 encryption.
  • Secrets Management: Application secrets and credentials are managed centrally using secure key stores with automated lifecycle management.
  • Data Access: Only authorized systems and personnel can access production data, following least-privilege and just-in-time access principles.

Solcoro does not collect or store end-user content; we analyze configuration metadata only, reducing exposure and ensuring compliance.

Solcoro's Cloud Infrastructure

  • The Solcoro platform is hosted on Amazon Web Services (AWS), leveraging modern, containerized infrastructure designed for scalability and resilience.
  • All systems are provisioned using Infrastructure as Code, ensuring every change is peer-reviewed, auditable, and version-controlled.
  • Solcoro environments are isolated by purpose to ensure operational safety and data segregation.

Data Retention & Deletion

Data Retention and Deletion

Solcoro collects only metadata from connected systems—never application data, tickets, documents, or messages. When you delete data or end your subscription, customer-identifiable information is removed from production systems within 30-90 days depending on the action taken. We may retain de-identified, aggregated data for industry benchmarks that cannot be traced back to any specific organization.

Key Timelines:

  • Active Deletion (user initiated): Up to thirty (30) days.
  • Subscription End: Up to ninety (90) days.

For full details, see our Data Retention and Deletion Policy

Authentication, Access & Monitoring

Authentication & Access Control

  • Single Sign-On (SSO): Solcoro only uses federated login via major identity providers using OIDC and SAML standards.
  • Role-Based Access Control (RBAC): Fine-grained permissions ensure users see only what they are authorized to access.
  • Internal Access: All administrative access is protected by multi-layered access controls.

Monitoring & Incident Response

  • Monitoring: Continuous metrics, logs, and traces for infrastructure and applications.
  • Alerting: Automated notifications for anomalous events and thresholds.
  • Response: On-call engineers and incident playbooks ensure rapid investigation and remediation.

Compliance & Responsible Disclosure

Compliance and Governance

Solcoro is pursuing SOC 2 Type II certification and operates in alignment with ISO 27001, GDPR, and DORA standards.

We regularly review our security controls and policies to ensure they meet or exceed modern compliance expectations.

Responsible Disclosure

Solcoro welcomes security researchers and partners to help us keep Solcoro secure.

If you believe you have found a security vulnerability in Solcoro, please report it to support@solcoro.com.

Solcoro takes all reports seriously and responds promptly.