Encryption in transit

Every connection to a SummaCore product is encrypted with TLS — browser to application, and between our internal systems.

Access control

All administrative accounts require multi-factor authentication. Administrative interfaces are not reachable from the public internet; they are accessible only over a private, authenticated network.

Tenant isolation

Our multi-tenant products enforce tenant separation at the database layer, so isolation does not depend on application code alone. Application database accounts run with least privilege.

Infrastructure

Production systems are hosted in US data centers. Public-facing services expose only standard web ports; everything else is closed to the internet and verified by periodic external scans. Public traffic to our applications is fronted by an edge network with DDoS mitigation.

Abuse and cost controls

AI-assisted features are protected by layered usage quotas and hard platform-level spending ceilings, so automated abuse cannot run unbounded.

Backups

Production databases are backed up automatically every day.

Incident response

We maintain documented incident response procedures, including denial-of-service response and credential-compromise runbooks. If an incident affects your data, we will notify you.

Reporting a vulnerability

We welcome good-faith security research. Report suspected vulnerabilities to security@summacore.com — include enough detail to reproduce the issue. We will acknowledge your report promptly and keep you informed as we investigate. We consider research to be in good faith when it: tests only against accounts and data you own; stops and reports immediately upon encountering data that isn't yours; avoids privacy violations, data destruction, and degradation of service — including high-volume automated scanning or scraping, which is not security research; and allows us reasonable time to remediate before any public disclosure. We will not pursue action against research conducted within these terms.

Questions

Security documentation for vendor assessments is available on request: security@summacore.com.

Last updated: August 27, 2026. This page reflects current practice and is updated as our security program evolves.