Security & Compliance

Security you can build on.

Core Registration is built for organizations that hold sensitive information about families, children and money. Here is how we protect it, in plain terms — and every package, the free one included, gets the same protection.

RLS
Tenant isolation
Enforced in the database, on every query
MFA
Staff authentication
Two-step sign-in with trusted devices
Audit
Audit trails
Health, money, e-signature and staff actions logged
Compliance

Designed around the rules you work under.

We built Core with these laws and standards in mind, and we give your legal and IT teams something concrete to review. Compliance is shared: we provide the controls and the agreements, and your own policies matter too. We don't claim certifications we don't hold.

HIPAA
Safeguards for protected health information, including minor records.
PCI DSS
Card data handled by our payment processor, never stored by Core.
COPPA
Protections for information about children under 13.
FERPA
Student records private to the school, behind role-based access.
GDPR
Collect only what you need, and export your records whenever you want.
e-Sign Act
Legally binding digital signatures on forms, waivers & contracts.
BIPA
Face matching in photo sharing only with consent, with limits on how long it is kept.

Security comes with every package.

Role, row and field-level access, tenant isolation in the database, audit trails and a HIPAA Business Associate Agreement come with every account. Not as add-ons. Not as enterprise upgrades.

Security architecture

Defense in depth — at every layer.

Access rules are enforced in the database itself, not only in the screens — so a mistake in one page can't show one organization's data to another.

01

RBAC × RLS × Field-Level Security

Role, row, and field-level access enforced top to bottom — internal staff, external attendees, and family-portal users each see only exactly what they should.

02

Encrypted & Tenant-Isolated

Encryption in transit and at rest, and each organization walled off from every other by row-level security in the database.

03

Audit Trails

Changes to health records, money, e-signatures and staff access are logged with who did what and when, so you can answer an auditor’s question.

04

MFA & Trusted Devices

Two-step sign-in (authenticator app) for staff, with trusted devices. Staff who can see health records or money are asked to turn it on.

05

Help With Your Review

A HIPAA Business Associate Agreement on every package, card data kept with our payment processor, and a team that answers your security questionnaire.

Need documentation for your security review?

Talk to our security team directly — we answer custom questionnaires and put a BAA in place before you send us a single record.

Ready to put Core Registration to the test?

Schedule a technical deep-dive with our security team and we'll walk through our controls architecture, answer your questionnaire, and provide a HIPAA BAA on request.