Privacy Policy
Effective date: June 12, 2026
1. Introduction
Command Operations & Readiness Engine ("C.O.R.E.," "we," "us," or "our") provides readiness and personnel management software for authorized military and organizational users. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you visit our public website, create an account, or use authenticated features.
By accessing C.O.R.E., you acknowledge this Policy. If you do not agree, do not use the platform.
2. Scope
This Policy applies to:
- Visitors to our public marketing pages (home, about, contact, legal pages)
- Registered users who authenticate into unit dashboards and command tools
- Administrators operating cross-unit or platform-level functions
- Information submitted through contact forms, support channels, or in-app feedback
C.O.R.E. is designed to complement—not replace—official Department of Defense, service component, or organizational record systems. Operational authority and official records remain with your command and governing systems of record.
3. Information we collect
Information you provide. Name, email address, phone number, organization, unit affiliation, role, rank, MOS, personnel and readiness data you or your leaders enter, messages, documents, training records, and contact-form content.
Automatically collected data. IP address, browser type, device characteristics, timestamps, pages viewed, diagnostic logs, and security events (e.g., failed sign-in attempts). We use this data to operate, secure, and improve the service.
Authentication data. Passwords are stored using one-way cryptographic hashing. Session identifiers are issued via secure, HTTP-only cookies and are not exposed to client-side scripts.
Sensitive operational data. Depending on unit configuration, the platform may process readiness-related information (e.g., training, medical status summaries, profile flags, weapons qualification status). Access is restricted by role and unit scope.
4. How we use information
- Provide, maintain, and secure the C.O.R.E. platform
- Authenticate users and enforce role-based access controls
- Enable unit readiness tracking, messaging, roster management, and reporting
- Respond to contact requests, demos, and support inquiries
- Detect, prevent, and investigate fraud, abuse, and unauthorized access
- Comply with legal obligations and enforce our Terms of Service
- Generate aggregated, de-identified analytics to improve reliability and performance
We do not sell personal information. We do not use personnel data for third-party advertising.
5. Legal bases (where applicable)
Depending on jurisdiction, we process personal data based on:
- Performance of a contract or provision of requested services
- Legitimate interests in securing and operating the platform
- Compliance with legal or regulatory obligations
- Consent, where required (e.g., optional analytics cookies)
6. Sharing and subprocessors
We may share information only as necessary with:
- Cloud hosting and database providers (infrastructure)
- Email delivery providers (transactional notifications and contact responses)
- Error monitoring and application analytics providers (service reliability)
- Your unit leadership and authorized administrators within scope of their roles
- Law enforcement or government authorities when required by valid legal process
Subprocessors are bound by contractual confidentiality and security obligations appropriate to the sensitivity of the data processed.
7. International transfers
Data may be processed in the United States or other jurisdictions where our infrastructure providers operate. Where required, we implement appropriate safeguards for cross-border transfers.
8. Retention
We retain information for as long as your account is active, as needed to provide services, to comply with legal obligations, resolve disputes, and enforce agreements. Contact-form leads and security logs are retained for defined operational periods and then deleted or anonymized unless a longer period is required by law or active investigation.
9. Security measures
We implement administrative, technical, and physical safeguards including:
- TLS encryption in transit for web and API traffic
- HTTP-only, Secure, SameSite session cookies
- Role-based access control and unit scoping
- Rate limiting on authentication and public endpoints
- Security headers (CSP, HSTS, frame denial, MIME sniffing protection)
- Production hardening: no client-exposed session tokens, minimized API payloads
- Monitoring for anomalous access patterns
No system is impenetrable. Users must protect credentials, report suspected compromise promptly, and follow unit information-security policies.
10. Your rights and choices
Subject to applicable law, you may request to:
- Access or correct personal information we hold about you
- Delete certain information where no legal retention obligation exists
- Object to or restrict certain processing
- Withdraw consent for optional cookies/analytics
- Receive a portable copy of data you provided, where technically feasible
Submit requests through our contact form. We may verify identity before fulfilling requests. Authorized command channels may also govern personnel records within the platform.
11. Children
C.O.R.E. is not directed to individuals under 18 and is intended for authorized organizational use. We do not knowingly collect data from children.
12. Changes
We may update this Policy to reflect operational, legal, or technical changes. Material updates will be posted on this page with a revised effective date. Continued use after changes constitutes acceptance.
13. Contact
Privacy inquiries: Contact C.O.R.E.
