Security
The case for this is that we hold less than the alternative.
So the useful version of this page is not a list of reassurances. It is what that actually gets you, what you can do to check each one yourself, and the places it falls short — that last part included because you would find them anyway.
What protects your group
Your group’s records cannot reach another group
Every workspace is sealed off from every other one. That seal is not a rule Coram is supposed to remember to follow — it sits underneath the whole product, so a mistake in one screen cannot walk around it.
Check it yourselfThis is the first thing the independent review is scoped to cover, and the review is published in full. Until it exists, /trust says so outright instead of implying otherwise.
There is no master key behind the screens you use
Nothing that answers when you load a page has the ability to ask for someone else’s records. Not for a support ticket, not for a debugging session, not for us.
Check it yourselfAsk us to look something up in another workspace for you. The answer is that we cannot, and it is the same answer every time, because there is nothing to make an exception with.
Messages and notes we are unable to read
Your channel messages and your organiser notes are scrambled on your own device before they ever reach us. We hold the scrambled version and nothing that would open it. Served with a warrant for them, we would hand over noise, and we would tell you we had.
Check it yourselfChange your workspace passphrase. Every message and every note stays readable to you straight away, and nothing gets re-uploaded to make that happen — which is only possible if the readable version was never ours to begin with. It takes about a minute.
Your password is not written down anywhere
We keep something that can confirm you typed your password correctly and cannot be turned back into the password. If our database were stolen tonight, it would not hand anyone the password you use — here or on the other sites people reuse it on.
Check it yourselfAsk us to send you your password. We will tell you we are not able to, and that refusal is the thing working. You can reset it; nobody, us included, can read it.
Nothing is kept just because deleting it is effort
Every kind of record here has a written expiry and a stated reason for it. The ones with a finite life are deleted on a schedule, by a machine, not when somebody gets round to it.
Check it yourselfAsk what we keep and for how long, about any specific thing in the product, and you get an answer in writing. A new feature that has no answer for its data does not ship — that is a build step, not an intention.
You can destroy a workspace, and mean it
A steward can end a workspace outright. The records are removed rather than hidden behind a flag, the uploaded files go with them, and our backups are short enough — a day at the outside — that no copy quietly outlives the decision.
Check it yourselfExport first: the export is built to be complete, so leaving is not the same as losing. Then destroy it, and try to sign back in. Nothing about that is reversible by us either.
The writing assistant is never told who anyone is
When Coram helps you draft a flyer or a letter, the people in it are taken out first. The assistant sees "the tenant" where your draft has a name, and the names are put back on your own screen afterwards. It is not that we ask it not to look — it is not given them.
Check it yourselfDraft something with real names and addresses in it and read what comes back. If a name ever survives where it should not have, that is a security report and we want it; the address is at the bottom of this page.
The automatic jobs are given as little as possible
The background work that keeps public facts current — who represents your district, when the council next sits — can touch those public facts and nothing else. It cannot see a contact, a workspace, or a word anyone typed.
Check it yourselfAlso inside the scope of the published independent review. It is the kind of thing that is easy to claim and hard to fake in front of somebody looking.
What we can see anyway
The things above are worth nothing if this part is vague, so it is not. Encryption covers what is said; it does not cover that a workspace exists.
We do not read your channel messages. They are encrypted before they leave your device, and nothing that would open them ever reaches us.
We do not read your organiser notes. Those are encrypted on your own screen, with a passphrase we never see.
We cannot check what is inside them for prohibited material, because most of what we hold is unreadable to us. That is the trade, and it is the right way round.
So enforcement here runs on reports, and on what is already out in the open — petitions, public event pages, fundraising pages. It is not, and cannot be, proactive surveillance.
What we do not have
This half is the point. Every security page lists strengths; the ones worth trusting say what is missing, in the same size type.
Nobody outside this project has tried to break it
There has been no independent penetration test. This is the largest gap on the page and it belongs at the top of it.
The commitment is an annual independent review, published in full and including the findings we have not fixed yet. /trust currently says that nothing has been published, because nothing has, and it will keep saying so until that changes.
Our SOC 2 review is our own, not an auditor’s
We have gone through the SOC 2 criteria ourselves, control by control, and we are working the results in order of how bad they were. Nobody independent has signed any of it, so there is no badge on this page — a badge would mean something we have not earned.
Marking your own homework is worth doing and worth exactly what it sounds like. What it has been good for is an honest written list of where we are weak, and several of the things on that list are already fixed. A real audit costs more than this project has, and no grassroots group has asked us for one; if a union or a funded coalition makes it a condition, we will pay for it and say so here.
You cannot read the code
Coram is closed source. That takes something real away from every claim above, and we are not going to pretend it does not.
What we offer in its place is a review we publish rather than a repository to read, a warrant canary signed by a person who is free to decline to sign it, and export tooling good enough that walking away costs you nothing.
We can still see the shape of your organising
Scrambling hides what your messages say. It does not hide that your workspace exists, roughly how many people are in it, or which weeks it is busy.
Nothing fixes this while we are the ones hosting it, and anyone who tells you otherwise is selling something. It is why the export path matters and why the canary exists.
Found something?
Write to security@coram.app, or use the details in security.txt. What we promise in return:
We answer within three working days.
We will not threaten a researcher who acts in good faith, and being thanked will never be conditional on staying quiet.
We publish findings we have not fixed, including in the annual review.
If a flaw exposed a workspace’s data, the people in that workspace are told what happened and when — whether or not any law requires it of us.
The reviews, the transparency report and the warrant canary are on /trust, which flags its own staleness rather than waiting to be asked about it.