At a glance
At Korefocus, data privacy and security are not optional — they are built into every layer of our technology and operations. We are committed to safeguarding your information and ensuring the reliable performance of our solutions.
- Privacy by Design: Clients retain full ownership and control of their data.
- No model training on client data: Your data is never used to train or improve AI models.
- Dedicated tenant per client: Each environment operates in complete isolation for maximum confidentiality.
- Flexible deployment: Cloud-hosted or on-premise, depending on your security and governance requirements.
- Microsoft Azure foundation: Hosted in EU datacenters with Microsoft Entra ID for SSO and MFA.
- Strict access management: Role-based controls, auditable connection logs, and enforced MFA protect every access point.
- Client-in-the-Loop authentication: Access sessions can be validated or terminated directly by the client, ensuring continuous visibility and control over data interactions.
- Data purge on demand: Clients can permanently delete all data and logs from Korefocus environments at any time, ensuring full control and GDPR-compliant data lifecycle management.
- Layered safeguards: Physical, administrative, and technical measures prevent unauthorized access and preserve system integrity.
- GDPR alignment: Supported by a comprehensive Data Processing Agreement and clearly defined controller/processor roles.
Data Usage and Privacy
- Client-exclusive data use: all client data processed through Korefocus solutions remain the sole property of the client.
- No model training on client data: Korefocus and third-party models does not use, share, or repurpose client data for training or improving its own or third-party models.
- Strict data isolation with dedicated tenant: Each client environment operates in a dedicated and secure context, ensuring full separation from other deployments.
- Data purge on demand: Clients can permanently delete all data and logs from Korefocus environments at any time, ensuring full control and GDPR-compliant data lifecycle management.
- Confidentiality commitment: All data handling strictly complies with contractual agreements, GDPR requirements, and the highest confidentiality standards.
Data Security
Korefocus ensures the highest standards of data protection and confidentiality throughout its infrastructure.
- Encryption: All client data is encrypted in transit using TLS and at rest using AES-256, ensuring comprehensive protection across all Korefocus environments.
- Hosting environment: Data is hosted exclusively on Microsoft Azure servers located within the European Union (Western Europe region), ensuring compliance with EU data residency requirements.
- Physical and operational security: Azure data centers operate under strict access control, continuous monitoring, and 24/7 on-site supervision.
- Compliance: Azure infrastructure supporting Korefocus services is independently audited and certified for major international standards, including SOC 2 Type 2, ISO/IEC 27001, and HITRUST CSF.
- Confidentiality commitment: All measures are designed to ensure that client information remains fully protected, private, and under the client’s sole control.
Hosting and Authentication
- The Korefocus solution is fully hosted on Microsoft Azure, benefiting from Azure’s global-grade reliability and compliance.
- All client data is exclusively stored on Microsoft Azure Cloud — no local storage is used in Korefocus-managed cloud deployments.
- Authentication relies on Microsoft Entra ID (formerly Azure Active Directory), with Single Sign-On (SSO) for Microsoft 365, Multi-factor authentication (MFA) available on demand (enforced for privileged access).
- Each Korefocus team member benefits from a single, named user account protected by a secure password with Multi-factor authentication (MFA).
Infrastructure and Access Control
- Access to services is strictly controlled and limited to authorized personnel only — the list of authorized users is defined in agreement with the client.
- Multi-factor authentication (MFA) is implemented throughout the infrastructure to minimize intrusion risks.
- Can be implemented upon request (free of charge):
- Client-in-the-Loop Authentication process for session-based access, further enhancing control and transparency
- A comprehensive connection log can also be implemented on client's demand, allowing consultation by the client at any time, providing detailed information on all data access, consultations, and modifications.
Deployment options
- Flexible architecture: Korefocus solutions can be deployed either in the cloud or on-premise, depending on client preferences and IT infrastructure.
- Confidentiality by design: On-premise deployment is available for clients who require maximum data protection and confidentiality, ensuring all AI workflows and data remain within their own secure environment.
- Regulatory compliance: Deployment mode can be aligned with internal governance policies, data residency requirements, and industry-specific compliance standards.
- Full control: Clients maintain complete ownership of their data, configurations, and access rights, while still benefiting from the full power of Korefocus AI solutions.
Data Governance: Roles & Responsibilities
At Korefocus, our clients remain the owners and controllers of their data — Korefocus acts solely as the data processor.
1. Definitions (European Commission):
- The Data Controller determines the purposes and means of personal data processing — deciding why and how the data is used.
- The Data Processor handles personal data only on behalf of the controller and under their instructions.
Source: European Commission – What is a data controller or data processor?
2. Accountability and compliance
- Korefocus is not responsible for the legal compliance of client-hosted data.
- Instruction-bound processing, Korefocus processes and stores data solely on the documented instructions of the client and for defined purposes, with no secondary use or sale.
- Korefocus is acting exclusively as a data processor. Where helpful, Korefocus can provide AI-powered discovery to help clients map and identify potential personal data within their environments.
- The client remains solely responsible for evaluating and ensuring the compliance of all data processed within the Korefocus environment.
3. Incident Notification
- Notify without undue delay (≤24h) after becoming aware of a personal data breach.
- Include nature/scope, likely consequences, measures taken, and a contact point.
- Provide updates, cooperate on GDPR Articles 33/34, and log notifications.
- Notices sent by email to designated contacts.