Security

Your workers' records, and exactly where they sit.

CORA holds identity documents, contracts and credentials for real people. You should be able to see where that lives and who touches it without having to email and ask.

Hosted in Australia

The CORA portal and the database holding your workforce records are hosted in Sydney. Uploaded documents sit in private Sydney storage that is not publicly addressable, so a document link cannot be guessed or shared out of the system.

We do not sell your data, and we do not use it to train anything.

Who we use, and what for

Provider What it does Where
VercelRuns the portalSydney
NeonThe database holding your workforce recordsSydney
Vercel BlobPrivate storage for uploaded documents and certificatesSydney
StripePayments. Card details never touch CORAGlobal

Those are the four that hold or run your records. We also use a small number of services for email delivery and course hosting. If you are running a procurement or vendor assessment and need the complete list with what each one receives, email hello@coraworkforce.com.au and we will send it.

Access is logged, and the log cannot be erased

Every time somebody opens a worker's document, that is recorded against the person who opened it. The log is append-only at the database level, which means the application itself has no ability to delete or alter it. If a contract was opened, that stays on the record.

This matters for the same reason it matters in a participant file. A record that can be quietly tidied up is not evidence.

One provider cannot see another

Each organisation's data is separated at the database level rather than by application logic. The isolation does not depend on the app remembering to filter correctly, which is the usual place that kind of thing goes wrong.

What a worker can and cannot do

A worker can add and replace their own credentials and see their own certificates. Only an administrator can delete a record. Supervision notes and performance reviews are never surfaced to a worker automatically. Feedback reaches them when somebody deliberately sends it.

Found a security issue?

Tell us at hello@coraworkforce.com.au. Machine-readable details are published at /.well-known/security.txt. We will acknowledge you, and we will not pursue anyone reporting in good faith.