Encryption at Rest
Sensitive identifiers and credentials are encrypted with AES-256-GCM before they are stored.
We only describe controls that are actually in place. This page is updated as capabilities are verified and released.
Sensitive identifiers and credentials are encrypted with AES-256-GCM before they are stored.
Passwords are stored only as salted bcrypt hashes; sessions are regenerated on sign-in.
Uploaded documents are validated by content and never exposed as public links.
Rate limiting, request-origin checks and strict input validation on every form.
Administrative actions and access to personal data are recorded.
Security capabilities of AnnCore HR and AnnCore Legal depend on the product and the deployment model (Cloud SaaS or On-Premise). We share the relevant security documentation during evaluation and on request.
If you believe you have found a security issue, please contact us through the contact page with the subject โSecurityโ. Please do not access data that is not yours.