Trust

Security at CoreFare

Protecting your transport data and transactions.

1. Our Commitment to Security

CoreFare is designed to securely manage critical transport operations, fare collection, and passenger mobility data. We employ advanced security protocols to ensure that every transaction, ticket, and piece of operational data remains confidential and tamper-proof.

2. Infrastructure and Data Protection

  • End-to-End Encryption: All data transmitted between the CoreFare app, terminals, and our cloud infrastructure is encrypted using TLS 1.3 or higher. Data at rest is encrypted using AES-256 standards.
  • Cloud Security: Our platform is hosted on world-class, ISO 27001-certified cloud infrastructure, ensuring high availability, continuous monitoring, and automated threat detection.
  • Regular Audits: We conduct periodic vulnerability assessments, penetration testing, and security audits to identify and mitigate potential risks proactively.

3. Identity and Access Management

Access to operational dashboards and passenger data is strictly controlled. We support role-based access control (RBAC), multi-factor authentication (MFA), and secure session management to prevent unauthorized access by personnel or external actors.

4. Payment Security

CoreFare integrates with PCI-DSS compliant payment gateways. We do not store full credit card numbers or sensitive payment authentication data on our servers. Closed-loop card transactions rely on secure, encrypted NFC and smart card protocols.

5. Incident Response

In the unlikely event of a security incident, our dedicated incident response team is prepared to act swiftly. We have established protocols for containment, investigation, and transparent communication with affected operators and regulatory bodies.

6. Reporting Security Issues

We welcome reports from security researchers and the community. If you believe you have found a security vulnerability in CoreFare, please report it immediately to info@coretech.com.ph.