Security & Compliance
Last Updated: September 1, 2026
At Corda, protecting your data and maintaining regulatory compliance is fundamental to everything we build. This page outlines our security practices, data handling policies, and the certifications we maintain.
Table of Contents
1. GDPR Compliance
Corda is fully compliant with the General Data Protection Regulation (GDPR). We ensure all personal data belonging to EU citizens is processed under strict lawful bases, including user consent and contract execution.
As a data subject, you maintain complete rights over your information. This includes the right to access, rectify, port, or erase your data from our systems at any time. Our Data Protection Officer (DPO) is dedicated to managing these requests promptly.
Cross-border data transfers are safeguarded using Standard Contractual Clauses (SCCs) to guarantee the same high standards of data security regardless of physical server locations.
2. Data Privacy
We collect only the essential personal data required to deliver our services, such as website URLs, contact names, and email addresses. This data is utilized solely for running campaigns and improving overall authority optimization.
Data retention is bound strictly to the active duration of your workspace. Inactive or deleted account data is permanently purged within 30 days of closure. We do not sell or share your data with third-party brokers.
Our cookie policies protect your anonymity. We use localized sessions only to maintain state and coordinate dashboard actions, and user consent mechanisms allow full opt-out capabilities on non-essential analytical tracking.
3. Security Practices
All data moving through the Corda platform is protected with industry-standard encryption protocols. We mandate HTTPS/TLS 1.3 for all data in transit and AES-256 block encryption for data stored at rest.
Access to internal systems is tightly audited. We employ strict role-based access control (RBAC) alongside mandatory multi-factor authentication (MFA) for all operations and support engineers.
Regular penetration tests are scheduled biannually with certified third-party cybersecurity firms. In the event of an anomaly, our specialized incident response team executes immediate container containment strategies and notifies affected users in under 72 hours.
4. Escrow Protection
To protect your long-term campaigns and operational investments, Corda maintains modern escrow agreements covering platform source code and database architecture backups.
Our trusted third-party escrow providers verify weekly builds and maintain secure air-gapped repositories. Conditions for escrow release are clearly defined to guarantee continuity in the highly unlikely event of platform insolvency.
We provide standard business continuity guarantees ensuring your existing published authority campaigns remain active and accessible under all circumstances.
5. Compliance Certifications
Corda has successfully obtained SOC 2 Type II certification. This validation reflects our adherence to rigorous operational parameters surrounding system security, availability, and processing integrity.
We conform strictly with the ISO 27001 standard for information security management systems and align database processing directly with CCPA guidelines for California consumers.
All financial transactions are routed directly via PCI DSS Level 1 compliant gateways, ensuring no raw credit card details ever traverse or settle on our core application systems.
Contact Security & Compliance
For security or compliance inquiries, please contact our team at compliance@corda.com