Security at Corealo
Operator connects to the systems that run owner-operated businesses. Protecting that access and the data behind it is foundational to how Corealo builds and operates the product.
Encryption
Sensitive data is protected in transit with TLS and at rest with industry-standard encryption. OAuth tokens and secrets are stored using dedicated encryption controls.
Least privilege
Access to production systems and customer data is limited to the people and services that need it, with permissions scoped to the minimum required for the task.
OAuth security
Operator connects to accounting, banking, payroll, and operational systems through OAuth where available. Tokens are handled carefully, refreshed securely, and revoked when connections are removed.
Secure cloud infrastructure
Corealo runs Operator on modern cloud infrastructure with network isolation, monitored environments, and hardened defaults appropriate for a production SaaS product.
Responsible disclosure
If you believe you have found a security issue, please report it to security@corealo.com. We take responsible disclosure seriously and will investigate reports promptly.
Report a vulnerability
Email security@corealo.com with enough detail for us to reproduce and assess the issue. Please do not include customer secrets or unnecessary personal data in your report.