Corners · Trust Center
Trust & Security
Corners is built for explorers, businesses and partners across Africa. Security and privacy are part of how we build, not an afterthought. This page summarises the controls that protect your data — and what we’re working on next.
Data protection & privacy
- GDPR-aligned: a Data Protection Officer is appointed and a Record of Processing Activities (RoPA) is maintained.
- Self-service data rights — access, export and deletion (DSAR) — handled from each account.
- Granular consent management and an auditable access log.
- EU data residency for core services (authentication and error monitoring run in the EU).
Encryption
- All traffic is encrypted in transit over TLS (HTTPS enforced, HSTS).
- Data is encrypted at rest by our managed database and object-storage providers.
- Secrets and tokens are stored encrypted, never in source control.
Access control
- Role-based access control with least-privilege staff tiers; side-roles are confined to their scope.
- Sign-in via Clerk with Google SSO; multi-factor authentication available.
- All privileged admin actions are recorded in an audit log.
Application security
- Strict per-request Content-Security-Policy (nonce-based, no unsafe-inline / unsafe-eval).
- Automated dependency scanning and an AI security review on code changes.
- OWASP-aligned security pipeline (SCA + DAST) with a documented risk-acceptance process.
- Prompt-injection and input guards on all AI endpoints; rate limiting on sensitive routes.
Infrastructure & availability
- Hosted on Vercel’s global edge network; managed PostgreSQL (Neon) with automated backups and point-in-time recovery.
- Bot protection and challenge handling via Cloudflare Turnstile.
- Infrastructure access is restricted and credential rotation is supported.
Monitoring & incident response
- Continuous error monitoring (Sentry, EU region) with AI-assisted triage.
- Proactive anomaly alerts routed to administrators.
- A defined process to investigate, remediate and communicate security incidents.
Payments
- Checkout is handled by hosted payment providers (Stripe, Flutterwave).
- Corners never stores raw card numbers — card data stays with the PCI-compliant processor.
Sub-processors
The third-party services we rely on to operate Corners. Each is bound by a data-processing agreement.
| Provider | Purpose | Region |
|---|---|---|
| Clerk | Authentication & user identity | US / EU |
| Neon | Managed PostgreSQL database | EU |
| Vercel | Application hosting & edge CDN | Global |
| Sentry | Error monitoring | EU |
| Resend | Transactional email | US / EU |
| Cloudflare | Bot protection (Turnstile) | Global |
| PostHog | Product analytics | EU |
| OpenRouter | AI model routing | US |
| Google Maps | Maps & geocoding | Global |
Compliance & documentation
• GDPR — DPO appointed, RoPA maintained, DSAR self-service. See our Privacy Policy.
• SOC 2 — not yet certified; Type 1 readiness is on our roadmap. We can share progress under NDA.
• DPA & security questionnaire — available on request for prospective and existing customers.
Report a vulnerability
Found a security issue? We appreciate responsible disclosure. Email security@corners.africa and we’ll acknowledge within 72 hours. Please don’t publicly disclose until we’ve had a chance to remediate.
This page is provided for transparency and does not form part of any contract. For data-processing terms, request our DPA.