Compliance & Certifications
KoreShield is designed to help organizations meet strict security and privacy standards. This guide outlines how our architecture supports compliance with major frameworks.KoreShield maintains SOC 2 Type II certification and provides features to help you meet HIPAA, GDPR, and PCI-DSS requirements.
SOC 2 Type II
KoreShield creates an audit trail that is essential for SOC 2 controls.Security Controls
Access Control
Role-Based Access Control (RBAC) ensures only authorized users can modify security policies.
Monitoring
Real-time logging of all security events and policy violations.
Change Management
Versioned policy configurations allow for safe rollbacks and change tracking.
Audit Logging
HIPAA Compliance
For healthcare organizations handling Protected Health Information (PHI).PHI Protection
- Redaction: Automatically detect and redact PHI (names, SSNs, medical record numbers) before data leaves your boundary
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- BAA: Enterprise plans include a Business Associate Agreement (BAA)
Technical Safeguards
GDPR Considerations
Data Sovereignty
KoreShield supports regional data residency to comply with GDPR data localization requirements.
- Region Locking: Configure KoreShield to process data only within specific EU regions
- Right to Erasure: API endpoints to delete all data associated with a specific user ID
- Data Minimization: We strictly limit data retention periods based on your configuration
Privacy by Design
PCI-DSS Requirements
For handling payment card information.Audit Logging for Cardholder Data
FedRAMP (Government)
KoreShield’s GovCloud deployment option ensures:- FIPS 140-2 Validated Encryption
- US Persons Only Support
- GovCloud Hosting
- Continuous Monitoring
FedRAMP High package available for government agencies. Contact sales for availability and pricing.
Data Retention Policies
Compliance Reporting
Common Questions
Is KoreShield HIPAA compliant out of the box?
Is KoreShield HIPAA compliant out of the box?
KoreShield provides HIPAA-ready features (encryption, audit logging, PHI redaction) but requires:
- Signed Business Associate Agreement (BAA)
- Proper configuration of PHI redaction policies
- Regular security assessments
- Staff training on HIPAA requirements
How do I comply with GDPR's right to data portability?
How do I comply with GDPR's right to data portability?
Use the data export API:This returns all data associated with the user in a machine-readable format.
What data does KoreShield store by default?
What data does KoreShield store by default?
By default, KoreShield stores:
- Scan results (threat type, confidence, timestamp)
- Metadata (user ID, request ID)
- Aggregated analytics
storeContent: true.Can I self-host KoreShield for compliance reasons?
Can I self-host KoreShield for compliance reasons?
Yes, enterprise customers can deploy on-premises or in private cloud using:
- Docker containers
- Kubernetes
- AWS/GCP/Azure private deployments
How do I handle data breach notifications?
How do I handle data breach notifications?
KoreShield provides automated breach detection: