Trust

Security at CoreAdmin

CoreAdmin is built for regulated fiduciary firms, so the platform's own controls are designed to the same standard we ask our clients to evidence. This page describes them in verifiable terms.

Hosting and data residency

Client environments run on Microsoft Azure in the North Europe region (Ireland), within the EU. Each client firm operates in its own dedicated, access-controlled environment. Network ingress can be restricted to a client's approved IP ranges, so the application is reachable only from authorised networks.

Encryption

Identity and access

Audit trails and evidence

Every module writes immutable, time-stamped audit records covering status changes, named actions, approvals and supporting evidence. Audit reports are filterable by actor, action and date range, and exportable, so any process can be reconstructed for management, auditors or an inspector on demand.

AI governance

AI in CoreAdmin prepares work; it does not approve it. Every AI-assisted action is logged to an AI-interaction register with the human decision recorded alongside, and reviewers see exactly what the AI produced or changed before signing. No AI output takes effect without a named person's decision.

Resilience

Certification status

CoreAdmin is not yet ISO 27001 certified. Our controls are documented and we support client due diligence directly: security questionnaires, architecture walkthroughs and control evidence are available on request as part of any evaluation.

We would rather state our certification position plainly than imply one. If your vendor due diligence requires specific evidence, ask: responding to it is part of how we work with regulated firms.

Reporting a concern

If you believe you have found a security issue in CoreAdmin or this website, please contact us via the enquiry form on the main site marking your message as security-related, and we will respond promptly.

Last updated: 2 August 2026