Families and firms trust Anchor Core AI with financial details, health questions, and personal data. That trust is the product. Here's exactly how that information is kept safe β in plain language, with no overstated claims.
βExcept the LORD keep the city, the watchman waketh but in vain.β β Psalm 127:1 Β· We build the walls, and we keep the watch β and we know Who keeps us.
Not a checkbox bolted on at the end β encryption, isolation, and access control are part of how the platform is built.
Every connection is protected with TLS/HTTPS in transit, and all data is encrypted at rest (AES-256) on the database. Nothing sensitive is ever stored or sent in the clear.
Each account's data is partitioned and protected by row-level security in the database. One account can never see another's clients, cases, or financials β it's enforced at the data layer, not just the screen.
Owner, admin, sub-admin, agent, and assistant each see only what their role allows β and it's enforced on the server, not just hidden in the UI. The financial and configuration back office is blocked at the edge for restricted roles.
Administrator accounts require multi-factor authentication (MFA) out of the box, and every password meets a strong complexity standard. Sessions end automatically after inactivity so an unattended screen can't be misused.
Read-only investigation seats, an assistant role with no access to financials or configuration, and credentials that are scoped to exactly what each person needs β nothing more.
A nightly self-healing audit and an on-demand deep-dive sweep every portal for integrity and connection issues, log them, and email the owner β so problems surface fast and don't sit silently.
Every privileged action β role changes, admin creation, credential resets, agency releases, configuration changes β is written to a tamper-resistant security log with the actor, target, time, and source, and reviewed in a daily digest. Accountability is recorded, not assumed.
Automated dependency and static-analysis scanning runs on every code change and on a schedule, so security flaws are caught and remediated on a tracked cadence β not discovered after the fact.
Automated backups run on managed, enterprise-grade infrastructure, so data can be restored after an incident or mistake.
For public-sector engagements we hold to the standards that matter β and we tell you plainly where we are on each. No overstated certifications, no security theater.
The platform is built to the control families that protect Controlled Unclassified Information (CUI): access control, audit & accountability, identity & authentication, configuration management, and system integrity. We maintain a documented System Security Plan (SSP) and a Plan of Action & Milestones (POA&M) β a self-assessment against all 14 control families, kept current as we pursue formal attestation.
Government customers can license Anchor Core to run in their own cloud tenancy (e.g. AWS GovCloud / Azure Government) β inside their existing accreditation boundary, with their identity, storage, and keys. The source and models stay ours; the data and environment stay yours.
Founded and led by a U.S. Coast Guard veteran (medically retired). Anchor Core is a veteran-owned small business. We hold no set-aside certification today, and we will never claim one we do not have pathways.
Anchor Core serves CUI and below. We do not process classified information on commercial infrastructure β classified engagements are pursued only through cleared prime partners and accredited environments. We scope procurement vehicles and accreditation properly before any deployment.
Financial figures, health questions, and personal information are encrypted, isolated per account, and restricted by role on the server. Sensitive collection is minimized, oversight roles are read-only, and the assistant role can't reach financials or configuration at all. Handling meets the safeguards HIPAA requires, and a HIPAA Business Associate Agreement (BAA) is available on request for protected health information.
Yes β in transit (TLS/HTTPS on every request) and at rest (AES-256 on the database). Passwords are salted and hashed, never stored in plain text.
Only your account. Data is isolated per account with database-level row security, and within your account each role sees only what it's entitled to. Owner/executive oversight is read-only when investigating, and the assistant role is blocked from financials and configuration entirely β enforced on the server.
No. Your data is yours. We do not sell, rent, or share it, and your client and agency data is never used for advertising. This is also written into your client agreement.
Data is stored in a US region on managed, SOC 2-compliant cloud infrastructure (Supabase/AWS for data, Vercel for the application) β our own SOC 2 attestation is on the roadmap β with automated backups for recovery.
It's protected with the safeguards HIPAA requires β minimized at collection, encrypted in transit and at rest, isolated per account, and restricted by least-privilege access with audited handling. A HIPAA Business Associate Agreement (BAA) is available on request for protected health information.
Anchor Core AI runs on SOC 2-compliant infrastructure (our own SOC 2 attestation is on the roadmap) and applies the full set of safeguards HIPAA requires β encryption, least-privilege access, per-account isolation, monitoring, and audit logging. A HIPAA Business Associate Agreement (BAA) is available on request for protected health information.
Issues are logged and surfaced immediately through the monitoring system. If an incident affected your data, you'd be notified directly and promptly, with a clear account of what happened and what was done.
Yes. Your data belongs to you β it can be exported, and on offboarding it is removed per your agreement. You're never locked in.
Access is founder-led and tightly held, on a least-privilege basis. Administrative database keys are server-side only and never exposed to browsers or third parties.
Yes β for Controlled Unclassified Information (CUI) and below. We align to NIST SP 800-171 controls with a documented SSP and POA&M, require administrator MFA, keep an immutable audit trail of privileged actions (reviewed daily), run continuous vulnerability scanning, and can license the platform to run inside your own accredited cloud boundary (e.g. AWS GovCloud / Azure Government). We are a veteran-owned small business and hold no set-aside certification; we will never claim one we do not have. Set-aside procurement. We do not process classified information on commercial infrastructure and will say so plainly β classified work is pursued only through cleared prime partners.
For administrators, yes β MFA is required by default, and every password must meet a strong complexity standard. Sessions also end automatically after inactivity. Individual agents can enable MFA as well.
Ask directly β you'll get a straight answer from the founder, not a sales script.