Corners · Centro de confiança
Confiança & Segurança
Corners is built for explorers, businesses and partners across Africa. Security and privacy are part of how we build, not an afterthought. This page summarises the controls that protect your data — and what we’re working on next.
Proof, not adjectives
4 of 4 controls confirmed within their own cadence, from the systems that run them.
- Encrypted backup, verifiedConfirmed2026-09-11
Last confirmed 2026-09-11. 109 tables, 103,912 rows, re-read and decrypted after writing.
Every night the database is snapshotted, encrypted and written off-site — then read back and decrypted immediately, so an unreadable backup fails the run instead of passing quietly.
- Cold archive read backConfirmed2026-09-07
Last confirmed 2026-09-07. The oldest backup kept, 13 days old, opened in 0.8 s.
Every quarter the OLDEST backup we still keep is downloaded, decrypted and unpacked — the check that catches an encryption key rotated out from under an archive. Re-importing into a live database stays a human step.
- Audit log sealedConfirmed2026-09-11
Last confirmed 2026-09-11.
The record of privileged actions is cryptographically sealed daily, so history cannot be quietly rewritten.
- Software bill of materialsConfirmed2026-09-11
Last confirmed 2026-09-11. CycloneDX 1.5, 726 production components.
Every release produces a CycloneDX inventory of what ships. We hand it over on request, with the digest of the file.
- AvailabilityMeasured externally
Measured by an independent monitor.
Target 99.5% monthly, watched by an independent uptime monitor.
Read from the systems that run these controls, refreshed every few minutes. We publish when a control last ran — never a live measure of how exposed we are, which would help the wrong reader far more than the right one. A control we could not confirm is shown as such rather than dropped from the list.
Data protection & privacy
- GDPR-aligned: a Data Protection Officer is appointed and a Record of Processing Activities (RoPA) is maintained.
- Self-service data rights — access, export and deletion (DSAR) — handled from each account.
- Granular consent management and an auditable access log.
- EU data residency for core services (authentication and error monitoring run in the EU).
Encryption
- All traffic is encrypted in transit over TLS (HTTPS enforced, HSTS).
- Data is encrypted at rest by our managed database and object-storage providers.
- Application-layer AES-256-GCM on top of that for the most sensitive material: MFA secrets, OAuth tokens and support-mandate details — with dedicated, rotatable keys.
- Daily encrypted off-site backups (AES-256-GCM); every backup is automatically re-read and decrypted after writing, so an unreadable backup raises an alert instead of a false sense of safety.
- Secrets and tokens never live in source control — a build-time guard enforces it.
Access control
- Role-based access control with least-privilege staff tiers; side-roles are confined to their scope, and elevated roles can carry an expiry date.
- Staff MFA is mandatory (TOTP), and phishing-resistant passkeys (WebAuthn) are required for top-level administrators — extensible per role.
- MFA and device approval are enforced on every admin request — not just at page load — and sensitive actions require a fresh re-authentication (step-up).
- Staff can only edit a claimed business’s content under a time-boxed mandate the owner issues and can revoke in one tap; private messages are never delegable.
- Leaver offboarding is a single action: sessions, roles, MFA, devices and mandates are revoked together. Access is reviewed quarterly.
- All privileged admin actions are recorded in an audit log that is cryptographically sealed every day — history cannot be quietly rewritten.
Application security
- Strict per-request Content-Security-Policy (nonce-based, no unsafe-inline / unsafe-eval).
- Automated dependency scanning and an AI security review on code changes.
- OWASP-aligned security pipeline (SCA + DAST) with a documented risk-acceptance process.
- Prompt-injection and input guards on all AI endpoints; rate limiting on sensitive routes.
Infrastructure & availability
- Hosted on Vercel’s global edge network; managed PostgreSQL (Neon) with point-in-time recovery, plus independent daily encrypted off-site backups (recovery objectives: RPO 24 h, RTO 4 h).
- Bot protection and challenge handling via Cloudflare Turnstile.
- Infrastructure access is restricted and credential rotation is supported.
Monitoring & incident response
- Identity threat detection (ITDR) replays the audit trail every 30 minutes against MITRE ATT&CK-mapped rules — including impossible-travel detection — with measured detection and response times.
- Continuous error monitoring (Sentry, EU region) with AI-assisted triage, and a watchdog that alerts when any scheduled safeguard goes silent.
- Real, audited containment actions (revoke sessions and devices, reset MFA, suspend) — suspending an account also terminates its sessions.
- A defined incident process with severity levels, and a blameless post-mortem within 48 hours for significant incidents.
Security governance
- A written security policy corpus (12 policies: access, change management, incidents, continuity, vendors, data handling…) grounded in how the platform actually works.
- An annual, documented risk assessment — including fraud scenarios — with named controls and accepted-risk decisions kept in a public-of-record register.
- A vendor register with criticality tiers and exit plans for every critical provider.
- Monthly, immutable evidence snapshots of security posture, backups and audit seals — our controls are designed for SOC 2 alignment. We do not yet hold an external SOC 2 attestation, and we won’t claim one until an independent auditor issues it.
Payments
- Checkout is handled by hosted payment providers (Stripe, Flutterwave).
- Corners never stores raw card numbers — card data stays with the PCI-compliant processor.
Subprocessadores
Os serviços de terceiros de que dependemos para operar a Corners. Cada um está vinculado a um acordo de processamento de dados.
| Fornecedor | Finalidade | Região |
|---|---|---|
| Clerk | Authentication & identity | USA |
| Neon | Primary database (Postgres) | EU (Frankfurt) |
| Vercel | Hosting, edge & Blob storage | Global edge |
| Resend | Transactional email | USA |
| Upstash | Rate-limiting (Redis) | EU (Frankfurt) |
| Stripe | Card payments | USA/EU |
| Flutterwave | African payments | Africa |
| Cloudflare | Turnstile CAPTCHA & image gen | Global edge |
| Google Maps | Maps & geocoding | Global |
| PostHog | Product analytics (consent-gated) | EU (Frankfurt) |
| Sentry | Error monitoring & masked session replay (debugging/security) | EU (Frankfurt) |
| OpenRouter | AI model routing (Ama assistant, agents, moderation) | USA |
| Travelpayouts | Affiliate link monetization (Drive) | Global |
Conformidade e documentação
• GDPR — DPO appointed, RoPA maintained, DSAR self-service. See our Privacy Policy.
• SOC 2 — not yet certified; Type 1 readiness is on our roadmap. We can share progress under NDA.
• DPA & security questionnaire — available on request for prospective and existing customers.
Comunicar uma vulnerabilidade
Found a security issue? We appreciate responsible disclosure. Email security@corners.africa and we’ll acknowledge within 72 hours. Please don’t publicly disclose until we’ve had a chance to remediate.
This page is provided for transparency and does not form part of any contract. For data-processing terms, request our DPA.