Data Security

Your receivables data is not our product.

Korrelo reads your invoice history to do its job — and nothing else. Here is exactly how we handle your data.

Core Principles

Four commitments we make to every customer.

Read-only ERP access

Korrelo connects through read-only OAuth 2.0 tokens. It cannot write, modify, delete, or create any records in your ERP or accounting system. Your data source is never touched — only read.

Data isolation per company

Each customer's data lives in a separate schema with isolated access controls. There is no shared data layer between customers. A bug affecting one company's data cannot expose another's.

Encryption at rest and in transit

All data stored in Korrelo's systems is encrypted at rest with AES-256. All data in transit between your ERP, Korrelo's servers, and your browser uses TLS 1.3. No unencrypted channels.

No data resale, ever

Your invoice data is never sold to third parties, never shared for marketing purposes, and never used to train AI models for other customers. What you bring in stays with you.

Technical Controls

Infrastructure and access controls.

For IT teams evaluating Korrelo before rollout. These are the controls in place as of June 2026.

Area Detail
Infrastructure AWS US-East-1 (Virginia). VPC with private subnets. No public-facing database endpoints.
Data backup Daily automated backups with 30-day retention. Cross-AZ replication for production databases.
Access control Role-based access control (RBAC). All admin actions logged with full audit trail. MFA required for all Korrelo staff access to production systems.
ERP token scope Read-only OAuth tokens scoped to AR module data only. Tokens revocable by customer at any time from the integrations settings page.
Incident response 24-hour SLA for critical security events. Customers notified within 72 hours of any confirmed breach affecting their data (per GDPR/CCPA requirements).
SOC 2 status Built with SOC 2 Type II controls in design. Formal third-party audit scheduled for Q1 2027. Current control set available on request for enterprise evaluations.
Data deletion Full data deletion within 30 days of account cancellation, confirmed in writing. Customers can request immediate deletion at any time.
Penetration testing Annual third-party penetration testing. Most recent test: Q4 2025. Summary report available to enterprise customers under NDA.

Have a security question before purchasing?

Our team responds to security inquiries within one business day. For enterprise evaluations, we can provide our security summary and control documentation.

Email [email protected]