generated: '2026-08-23' method: searched source: https://trust.kore.ai/ url: https://trust.kore.ai/ platform: SafeBase by Drata access: >- The index of documents and the certification list are public. The underlying reports and policies are request-gated (NDA/approval), which is the normal SafeBase posture. probe: url: https://trust.kore.ai/ curl_status: 403 curl_note: >- A plain curl with a browser User-Agent receives a Cloudflare interstitial ("Just a moment...", noindex/nofollow). The page renders normally in a browser. This is an edge bot policy, NOT a dead page — it is recorded as live. browser_render_status: 200 checked: '2026-08-23' certifications: - SOC 2 Type 2 - PCI DSS - ISO/IEC 27001:2022 - GDPR - CCPA - EU AI Act - DESC Cloud Service Provider document_categories: - Information Security Overview and Policy - Vulnerability Management Process and SLA Policy - Data Security (encryption at rest and in transit, backups, customer data protection) - Secure Software Development Life Cycle - Responsible AI Framework - AI Transparency and Explainability (bias and hallucination monitoring) - Product security (SSO, RBAC, MFA) - Infrastructure and network security (firewall, anti-DDoS) - Business continuity and disaster recovery - Incident response and management - Security awareness and training policies legal_and_commercial_documents: - Certificate of Liability Insurance - Enterprise Service Level Agreement - Platform License Agreement in_product_security_controls: note: >- Beyond the trust center, the platform ships customer-facing controls documented in the release notes and admin docs — BYOK/KMS with Azure Key Vault and AWS, a selectable KMS compliance level of GDPR / SOC2 / NIST enforced at configuration-write time, split DEK-retirement and KEK-rewrap key rotation with preflight checks, PII protection, guardrails, and a session-scoped encrypted secret vault that keeps tool-returned credentials out of the LLM context. sources: - https://docs.kore.ai/agent-platform/administration/security-observability-settings - https://docs.kore.ai/agent-platform/pii-protection - https://docs.kore.ai/agent-platform/release-notes/recent-updates vulnerability_disclosure: public_policy: false bug_bounty: false note: >- NO public vulnerability disclosure path was found. /.well-known/security.txt returns 404 on www.kore.ai, docs.kore.ai and agents.kore.ai and 403 on platform.kore.ai and bots.kore.ai; no HackerOne, Bugcrowd or Intigriti program was found; and no /security or /responsible-disclosure page exists (www.kore.ai/security returns 404). The trust center lists a "Vulnerability Management Process and SLA Policy" document, but that is an internal process description behind the request gate, not a route for an outside researcher to report a finding. Because there is no public route, this repo emits no Security / VulnerabilityDisclosure pointer.