How your data is protected
A hospital, a school and a lender all ask the same question before they commit: where does our data actually sit, and who can reach it? Here are the answers.
Last updated 23 August 2026
Your own space, not a shared pool
Each customer runs in a separate space with its own database and its own login. Your records are not mixed into a shared table with other organisations’ records, so there is no query that could return someone else’s data by mistake.
Who can open what
- Access is granted by role, not by seniority — a clinician sees the patients they treat, a bursar sees fees, a teacher sees their own classes
- Sensitive modules such as the data room are opened per person, per document
- Permissions can be withdrawn instantly, and take effect on the next request
- Nothing is public by default
A record of who did what
Every opening, edit, download, approval and permission change is written to an audit log with the person, the record and the time. The log can be exported for an auditor and cannot be edited from inside the application.
In transit and at rest
- All traffic is over HTTPS; plain HTTP is redirected, never served
- Passwords are stored as salted one-way hashes — we cannot read yours
- Database backups are encrypted and held separately from the live system
- Files in the data room can be watermarked with the viewer’s name
Backups and getting back up
- Automatic daily backups, retained on a rolling schedule
- Restores are tested, not assumed
- Your data is yours — you can export it in a standard format at any time, and you get a full export if you ever leave
This website itself
The site you are reading is deliberately plain: no tracking, no analytics, no third-party scripts. It sends a strict Content-Security-Policy, refuses to be framed, forces HTTPS, blocks directory listing, and keeps enquiry files unreachable from the web. The demo form is rate-limited and protected against automated abuse.
Where responsibility sits
When Corenta runs your institution, you are the data controller — the records belong to you and the decisions about them are yours. We are the processor, acting on your instructions. That split is written into the agreement, along with breach notification and what happens to your data at the end.
Reporting a problem. If you believe you have found a security weakness, write to hello@corenta.com with enough detail to reproduce it. Report it privately and give us reasonable time to fix it, and we will not pursue you for having looked.
Questions before you commit
If your board, your funder or your auditor has a security questionnaire, send it. Answering it properly is part of the sale, not an obstacle to it. Ask us anything.