Approvals & sign-off
Approve-first is the default, per brand and per channel. Sensitive accounts can require a named approver or two-person (maker ≠ checker) sign-off before anything ships. An API key is recorded as a machine actor, never a person, so it can never stand in as the second approver.
Disclosure built in
Sponsored posts are auto-stamped with #ad / paid-partnership disclosure, aimed at FTC and ASCI guidance — applied by the publishing path, not left to anyone to remember.
Tamper-evident audit
Every governance action is written to a hash-chained trail. Removing or altering a sealed record is detectable, and the chain head is printed on every CSV and PDF export so you can prove later what was approved, by whom, and when.
Hard limits
The engine never runs paid ads and never sends one-to-one direct messages, at any autonomy setting. Per-workspace velocity limits are derived from your own plan and clamped by an absolute ceiling no plan or override can exceed.
Hardened by default
TLS with HSTS, a strict Content-Security-Policy, frame-deny, request size limits, upload validation by true file type, SSRF protection on outbound calls, per-IP and per-action rate limiting, and containers that run as a non-root user.
Crisis ready
A live war-room detects reputation spikes, pauses automation, and resumes cleanly once the moment passes — with a compiled post-mortem. An operator kill-switch can stop automated publishing outright.
Where your data lives
Data is stored in India. That is the only region we operate — there is no EU, Singapore or US shard, and no way to move a workspace to one.
The region is not a label on a settings page — it decides which database holds your rows. A request for data a given node does not hold is refused outright, naming the node that does hold it, rather than quietly served from somewhere else. That refusal is the whole point: telling you your data is in one place while it sits in another is the failure this design exists to prevent.
Backups and recovery
Encrypted automated backups, 7 daily / 4 weekly / 12 monthly, stored in the same region as the data, with restores verified by an automated job. That job restores the newest backup into a scratch database and checks it is real; if it fails, goes stale or has never reported, it wakes someone up.
Point-in-time recovery is not enabled, so do not plan around sub-daily recovery granularity. Backups include roles and grants as well as data, because a dump without them restores into a database the application cannot log in to.
Your data, and getting it out
Every category of operational data has a retention window and ages out on a schedule — raw social-listening mentions after 180 days (30 days for anything retrieved from the YouTube API, which is YouTube's own limit), notifications after 90, and so on. Workspaces can tighten those windows. Legal hold stops all automated deletion for an account.
You can export your content, contacts and full audit trail at any time. Deleting a workspace erases it in every region we can reach and leaves only a tombstone containing no personal data. The full schedule and the honest limits are in the Privacy Policy; step-by-step removal instructions are on the data deletion page.
Every third party that can receive data is listed publicly, with purpose, data categories and region, on our sub-processors page. We give 30 days' notice before that list changes. We use no third-party product analytics, no error-tracking service, no advertising pixels and no session replay.
AI, and what we do not do with your data
Content is AI-generated and a human approves it. We do not train models on your data — there is no training or fine-tuning pipeline in the product. Outcome learning adjusts scoring weights inside a single workspace, on that workspace's own results; nothing learned in yours is applied to anyone else's.
Where we call Anthropic or OpenAI directly, their API terms state inputs are not used to train their models. Where the configured provider is OpenRouter, requests are brokered onward and we cannot give one no-training guarantee across every model reachable that way — ask us and we will pin your workspace to a direct provider. Exported creative carries a real C2PA Content Credentials manifest recording that it was AI-made — readable by any C2PA tool, and tamper-evident.
Built like infrastructure.
CoreLayerEngine is built and operated by Ektasi Technology (OPC) Private Limited, an India-based software company, from a registered office in Varanasi, Uttar Pradesh.
Read our story →Governed autonomy, out of the box.
Turn it on with confidence. Start free and set your guardrails in minutes.