Security Overview

Security controls for serious business operations.

KORE1st is planned with controlled workspace access, company-wise permissions, secure domain mapping, 5GB included file storage, own cloud options, customer-owned database options, and clear platform ownership boundaries.

Shared responsibility

Clear ownership before activation.

KORE1st manages the platform experience and internal platform code. Customers manage their authorized users, data accuracy, credentials, domain ownership, uploaded content, media annotations, and any responsibilities agreed for customer-owned database or own cloud hosting.

No admin panel handover

Provider console access remains internal.

No source code transfer

Repositories and build internals are not shared.

Controls

Security areas covered during onboarding

Exact responsibilities can vary by subscription, infrastructure choice, database arrangement, and implementation scope.

Separated business workspace

KORE<sup>1st</sup> is designed so each subscribed business works inside its own workspace, companies, users, permissions, and business records.

Role and permission control

Access is controlled through assigned users, roles, permissions, and company-level scopes so teams only see the operational areas they are authorized to use.

Custom domain safety

Custom domain or subdomain mapping requires ownership verification, DNS alignment, SSL readiness, and technical approval before activation.

Customer-owned database option

When a customer-owned database is approved, connection access, hosting security, backups, credential handling, and availability expectations are documented during onboarding.

Own email sending setup

Eligible customers can store their own SMTP settings in the approved business setup and send supported emails through their provider.

5GB included file storage

Subscribers receive 5GB included storage for file uploads. Additional storage can be expanded with approved commercial scope and operational limits.

Own cloud storage

Approved customers can configure Amazon S3, Azure Blob, DigitalOcean Spaces, Wasabi, Cloudflare R2, MinIO, or S3-compatible storage with clear access and security ownership.

Media annotation safety

Image and video annotations can be attached to operational records, so permissions, visibility, retention, and sensitive media handling should be planned during onboarding.

Backup and restore planning

Backup strategy, retention expectations, recovery ownership, and restore process should be finalized during implementation, especially for own-database setups.

Audit-aware operations

Approvals, notifications, reports, templates, and controlled workflows help teams track operational actions and reduce unmanaged changes.

Source code boundary

KORE<sup>1st</sup> is delivered as managed subscription software. Clients can use the subscribed service, approved domains, and approved database setups, but source code and repositories are not shared.

Incident response path

Support channels, severity, required customer contacts, technical evidence, and data handling obligations should be agreed for enterprise onboarding.

Customer checklist

What customers should prepare

A cleaner onboarding starts with the right operational information ready before domain or database activation.

Owner
Domain
DB
Cloud
Roles
Secure setup
SSL ready
Access verified
Backup plan
Authorized business owner and technical contact
Company list, user roles, and approval matrix
Domain or subdomain ownership access
Database hosting and backup responsibility if own DB is requested
Cloud storage provider, bucket/container access, CORS, retention, and backup responsibility
Uploaded image/video sensitivity and annotation visibility rules
Data retention, restore, and support escalation expectations
Internal policy for password, MFA, and user offboarding