HomeCompliance
Trust & Safety

Compliance &
Trust Center

We believe responsible technology starts with accountability. This page documents how Corevia Technologies approaches data privacy, AI ethics, security, and regulatory compliance.

Last reviewed: January 2025 · Updated quarterly

Data Privacy
Compliant
Responsible AI
Ongoing
Security
Compliant
Accessibility
In Progress

This page reflects Corevia's current compliance posture as of January 2025. It is informational only and does not constitute legal advice. For formal compliance documentation, data processing agreements, or security questionnaires, contact [email protected].

Data Privacy & Protection

Compliant

CCPA (California Consumer Privacy Act)

Active

We honor all California resident rights including the right to know, delete, and opt out of sale of personal information. We do not sell personal data.

COPPA (Children's Online Privacy Protection Act)

Active

Our platforms require users to be at least 13 years of age. We do not knowingly collect personal information from children under 13 without verifiable parental consent.

GDPR Alignment

Best Practice

While Corevia is a U.S.-based company, we apply GDPR-aligned data minimization, purpose limitation, and user rights principles across all platforms as a best practice.

Responsible AI & Ethics

Ongoing

Bias & Fairness Auditing

Ongoing

We conduct regular audits of our AI models to identify and mitigate demographic bias. Our evaluation frameworks test for disparate impact across protected characteristics.

Explainability Standards

Active

Where AI outputs affect user decisions — in career guidance, legal analysis, or educational assessment — we provide human-readable explanations of how conclusions were reached.

Human-in-the-Loop Safeguards

Active

High-stakes AI outputs (e.g., contract risk flags in RedlineIQ, diagnostic suggestions) are clearly labeled as AI-assisted and designed to support, not replace, professional judgment.

Security Standards

Compliant

Encryption in Transit & At Rest

Active

All data transmitted to and from Corevia platforms is encrypted using TLS 1.2+. Stored data is encrypted using AES-256 at rest across all production systems.

Access Control & Least Privilege

Active

We enforce role-based access controls (RBAC) and the principle of least privilege across all internal systems. Access to production data requires multi-factor authentication.

Vulnerability Management

Active

We conduct regular penetration testing and maintain a responsible disclosure policy. Critical vulnerabilities are patched within 24 hours; high-severity within 72 hours.

Accessibility

In Progress

WCAG 2.1 AA Alignment

In Progress

We are actively working toward WCAG 2.1 Level AA conformance across all Corevia platforms. Our design system enforces minimum contrast ratios, keyboard navigation, and semantic HTML.

Screen Reader Compatibility

In Progress

Core user flows across our platforms are tested with NVDA and VoiceOver to ensure compatibility with assistive technologies.

Compliance Requests & DPAs

For data processing agreements, security questionnaires, formal compliance documentation, or to exercise your data rights, reach our compliance team directly.