Legacy Core™

Security Practices

Legacy Core™ is a credentialing authority. We hold our own systems to the same discipline we ask of the businesses we credential: least-privilege access, live verification against the Public Business Trust Registry, and a fixed review cadence — without overclaiming what a Trust Badge can promise.

Live Registry Verification

Verification happens in the registry, not on the badge. Every Trust Badge resolves to a live record in the Public Business Trust Registry. Scanning the QR code or entering the credential ID checks status against our system of record in real time. A badge that is not in the registry does not verify. Credential status — active, renewal due, or revoked — stays current because it is never cached on the badge itself.

Access Control & Admin MFA

Admin, business, and Alliance Partner portals use role-based access with ownership checks. MFA is required on every administrative account — authenticator apps (TOTP) plus optional phishing-resistant passkeys, with backup codes. Destructive credential actions require a fresh MFA step-up. Login lockouts and hashed, single-use reset and invite tokens reduce account takeover risk.

Encryption & Confidentiality

Data in transit uses TLS. Sensitive readiness assessment posture answers are encrypted at rest with envelope encryption. Private storage is served only through short-lived, server-signed URLs. Service-role and signing secrets stay on the server — CI blocks them from shipping in client bundles.

Payments Without Card Storage

All payments are processed by Stripe (PCI DSS Level 1). Legacy Core never stores, processes, or transmits credit card or bank account information. Webhook events are signature-verified, idempotent, and dead-lettered on failure so retries do not silently double-fulfill.

Integrity & Audit Trail

Credential issuance follows manual review before a Trust Badge goes live. Credentialing events write to a hash-chained audit log with immutability controls. Scoring and grading for readiness assessments run server-side so clients cannot alter results.

Monitoring & Biweekly Checkups

Automated monitors watch for password-reset floods, elevated invalid QR scan rates, flagged IPs, webhook dead letters, and elevated risk scores — and alert the security inbox by email. Biweekly security checkups (1st and 15th) combine runtime signals with dependency audit and SBOM snapshots for human review.

Incident Notice

Legacy Core investigates security incidents promptly and provides notices as required by applicable law and contract, without unreasonable delay. Specific timing depends on the facts, affected information, law-enforcement needs, and any sector-specific requirements.

California Privacy Requests

Legacy Core maintains processes for California privacy requests where applicable. See our Privacy Policy for scope, rights, and request methods.

Infrastructure Partners

The registry runs on infrastructure providers that publish SOC 2 and/or PCI DSS attestations for their platforms, including Supabase, Vercel, Stripe, GitHub, and Google Cloud. Platform controls such as encryption at rest, DDoS mitigation, and isolated deployments are part of that foundation.

Our Commitment

We practice what we credential. Legacy Core carries cybersecurity and E&O insurance, maintains a documented incident response plan, runs continuous monitoring with email alerts, and completes biweekly security checkups plus quarterly operational reviews. Responsible disclosure: report issues to security@legacycore.com. Our Privacy Policy and Terms of Service are linked below.

Questions about privacy or data rights? privacy@legacycore.com

Privacy Policyprivacy@legacycore.comTerms of ServiceRefund PolicyHow We Protect Your Data
Security Practices | Legacy Core™ | Legacy Core