Hosting and data residency
Client environments run on Microsoft Azure in the North Europe region (Ireland), within the EU. Each client firm operates in its own dedicated, access-controlled environment. Network ingress can be restricted to a client's approved IP ranges, so the application is reachable only from authorised networks.
Encryption
- All traffic is encrypted in transit with TLS.
- Data is encrypted at rest on Azure-managed storage and databases.
- Particularly sensitive records (for example suspicious activity report content) carry an additional layer of application-level encryption, so they are unreadable even with direct database access.
Identity and access
- Single sign-on with Microsoft Entra ID is supported, alongside managed email and password sign-in.
- Role-based access control with a tiered permission catalogue: module access, sensitive views, approval and sign-off, financial authorisation, and statutory restricted tiers are granted separately.
- Segregation-of-duties conflicts are defined centrally, and every permission change is recorded in an append-only access audit log.
- Statutory perimeters are enforced in software: suspicious activity report content is restricted to the MLRO and Deputy MLRO.
Audit trails and evidence
Every module writes immutable, time-stamped audit records covering status changes, named actions, approvals and supporting evidence. Audit reports are filterable by actor, action and date range, and exportable, so any process can be reconstructed for management, auditors or an inspector on demand.
AI governance
AI in CoreAdmin prepares work; it does not approve it. Every AI-assisted action is logged to an AI-interaction register with the human decision recorded alongside, and reviewers see exactly what the AI produced or changed before signing. No AI output takes effect without a named person's decision.
Resilience
- Databases are backed up automatically with point-in-time restore, managed by Azure.
- Application health is monitored continuously with automated probes.
Certification status
CoreAdmin is not yet ISO 27001 certified. Our controls are documented and we support client due diligence directly: security questionnaires, architecture walkthroughs and control evidence are available on request as part of any evaluation.
Reporting a concern
If you believe you have found a security issue in CoreAdmin or this website, please contact us via the enquiry form on the main site marking your message as security-related, and we will respond promptly.
Last updated: 2 August 2026