Security
Security
Last updated 9 September 2026. Applies to corefeld.com and to software CoreFeld builds, deploys and supports for clients.
The short version. CoreFeld follows the NIST Cybersecurity Framework 2.0, with control selection informed by CIS Controls v8, Implementation Group 1. It holds no SOC 2 and no ISO 27001 certification and does not imply one. The default deployment model is that the customer runs the system in their own environment and receives the source, so the customer holds the keys, the logs and the data. Where a buyer needs certification rather than evidence, we say so before the bid rather than after.
What we certify, and what we do not
CoreFeld LLC was formed on 3 August 2026. Attestation reports describe a control environment operating over a past period, and a company that has not existed for that period cannot honestly produce one.
| Item | Status |
|---|---|
| NIST CSF 2.0 alignment, documented and evidenced per engagement | Yes |
| CIS Controls v8 IG1 informing control selection | Yes |
| Customer-led security review, questionnaire response, architecture walkthrough | Yes, on every engagement, at no charge |
| Customer-run penetration test or vulnerability scan against the delivered system | Permitted and welcomed |
| SOC 2 Type I or Type II | Not held |
| ISO/IEC 27001 certification | Not held |
| FedRAMP authorisation | Not held. CoreFeld does not operate a multi-tenant cloud service offering |
| Reported security compromise or breach since formation | None |
The deployment model is the security posture
CoreFeld's default is not a hosted multi-tenant service. It is a system that runs in the customer's own cloud subscription or on the customer's own infrastructure, delivered with its complete source under a perpetual customer licence. The practical consequences are the ones a security reviewer actually cares about:
- No standing vendor access. The customer holds the credentials. Support access is requested, granted by the customer, time-boxed, and recorded in the customer's own audit trail.
- No vendor data store. Customer records, keys, logs and backups stay inside the customer's boundary and under their retention and residency rules.
- No shared blast radius. One customer's deployment is not adjacent to another's, because there is no shared tenancy.
- No lock-in as a security dependency. If CoreFeld ceased to exist tomorrow, the customer keeps a running system and the source to maintain it.
Where a customer prefers CoreFeld to host, we do — in a dedicated, single-tenant environment in a United States region, encrypted in transit and at rest, with data returned in an open format and destroyed at contract close. That is an option offered for convenience, not the architecture's requirement.
How the software is built
- Identity is federated, never invented. SAML/ADFS, OIDC, Microsoft Entra ID and Google Workspace. CoreFeld systems do not store customer passwords.
- Least privilege by role, with authorisation enforced server-side on every request rather than by hiding interface elements.
- Small dependency surface, deliberately. Products are built on the platform runtime with minimal third-party packages, because every dependency is an advisory you will have to answer for later. Dependencies are scanned on every build.
- Audit logging as a product feature. Decisions that affect people — an assignment, an approval, a release, a consent change — are recorded with actor, timestamp and inputs, so the record answers a dispute rather than reconstructing one.
- Tests are the control evidence. Authorisation, consent, retention and accessibility rules are executable tests that run on every change, not a paragraph in a policy.
- Secrets never live in source. Configuration is environment-supplied; repositories carry no credentials.
Artificial intelligence
CoreFeld's delivered products do not send customer data to any AI service, and no customer data is ever used to train any model. Where a customer specifically wants an AI-assisted feature, it is enabled only in a resource the customer controls, under a written approval that names the data involved. Decision logic that affects a person's pay, hours, eligibility or access is implemented as deterministic, documented, auditable rules — because a decision that cannot be explained cannot be defended.
This website
corefeld.com is a static site on Cloudflare Pages with no customer data in it. Its response headers are part of the deploy artifact and are checked in with the site:
- HSTS with a one-year max-age,
includeSubDomainsandpreload - A Content Security Policy with no
unsafe-inlineand nounsafe-eval,frame-ancestors 'none',object-src 'none'andbase-uri 'none' X-Frame-Options: DENY,X-Content-Type-Options: nosniff, a strictReferrer-Policy, a restrictivePermissions-Policy, and cross-origin isolation headers- The contact form posts to this origin only and is protected by Cloudflare Turnstile
What the site collects and how long it is kept is in the privacy notice.
Report a vulnerability
If you believe you have found a security issue in corefeld.com or in software CoreFeld has delivered, tell us at security@corefeld.com, or through the contact form if you would rather not send mail. Include what you found, where, and how to reproduce it.
- A human acknowledges within two business days.
- You get an assessment with a severity and a target remediation date within ten business days.
- Good-faith research that stops at proving the issue — no data exfiltration, no service disruption, no access to other people's data — will not be met with legal action from CoreFeld.
- Where the affected system belongs to a CoreFeld client, we will notify them and coordinate disclosure with them. We will not disclose your report to anyone else without telling you.
We would rather hear about it than have it stay broken. The same sentence is on the accessibility statement, and it is meant literally in both places.
Documentation available to buyers on request
At no charge, before or during a procurement: architecture and data-flow description, control mapping to NIST CSF 2.0, completed security questionnaires including HECVAT and buyer-specific forms, subprocessor list, retention and destruction schedule, incident-response process and notification commitments, business-continuity approach, and the accessibility conformance report described on the accessibility statement. Ask through the contact form or call (507) 900-9300.