Skip to main content
Legal center

Perpetual Core / Legal

Security & Data Practices

A plain-language description of Perpetual Core's security approach and the evidence buyers should request for a specific deployment.

Effective August 29, 2026

Security principles

  • Collect and retain only information needed for a defined purpose.
  • Use individual authentication, least privilege, and separated customer or entity boundaries.
  • Encrypt supported traffic in transit and use provider-supported encryption at rest.
  • Keep consequential actions reviewable and attributable.
  • Use controlled secrets and avoid embedding credentials in source code.
  • Maintain incident, vulnerability, backup, and recovery procedures proportionate to the service.

Customer diligence

Before production use, buyers should request the deployment-specific architecture, subprocessors, data flows, retention, access model, recovery objectives, incident terms, test evidence, and any required regulatory agreement. Public marketing language does not replace that review.

Regulated environments

Healthcare, education, government, financial, and other regulated deployments require an expressly scoped environment and written terms. Do not infer HIPAA, FERPA, PCI DSS, SOC 2, FedRAMP, or other compliance from general security practices. Perpetual Core will state a certification or regulated authorization only when current evidence supports it.

Report a vulnerability

Send a concise description and reproduction steps to info@perpetualcore.com with the subject line ‘Security report.’ Do not access, alter, retain, or disclose data that is not yours; do not disrupt service; and allow a reasonable period for investigation before public disclosure.