الأمان

الأمان model: end to end encryption, key continuity, and verification-friendly records.

Core51 security is designed to hold up in real deployments where perfect trust is not realistic. Messages are encrypted on device and decrypted only by participants. The server stores ciphertext and routing metadata, which makes confidentiality resilient even if the infrastructure is compromised. Key continuity is enforced with TOFU: on first contact, keys are pinned, and changes require explicit re trust. This protects against silent interception, including scenarios where an attacker attempts to rotate keys without user awareness. We also focus on operational security signals. Key rotations can be reviewed, and integrity related metadata supports later verification. This is important for audits: you want to demonstrate what controls existed, how changes were handled, and what proof is available. The end result is a security story that a CISO can explain, a compliance team can document, and a product team can operate without custom exceptions.

End to end encryption (E2EE)

Message content is encrypted on the sender device and decrypted only on participant devices. The server stores ciphertext and delivery metadata.

Key continuity (TOFU)

Keys are pinned on first contact. If a peer key changes, clients warn and require explicit re-trust. This reduces silent interception risks in environments where the server cannot be fully trusted.

Rotation visibility

Key changes are observable and can be reviewed. A rotation history enables investigation of suspicious events and supports incident response playbooks.

Integrity signals

Core51 maintains integrity-related metadata (hashes/chain state) to support later verification of exports. The goal is to make tampering and selective omission detectable in the supported model.

Server security boundary

The design assumes the server can be compromised. Confidentiality comes from E2EE; integrity comes from signatures and commitment hashes; continuity comes from pinned keys on clients.

Audit-friendly logging

الأمان relevant events (authentication, key events, verification checks) are meant to be reviewable without needing server access to plaintext.

Business value

Built for teams that get audited

الأمان without trusting the server

Confidentiality comes from E2EE. Integrity comes from signatures and commitments. Continuity comes from pinned keys.

Key events you can explain

Key rotation visibility helps security teams investigate anomalies and document remediation steps.

Audit program

جاهز للتدقيق

External audits on a regular schedule

Core51 is designed to support independent, external security reviews. We provide a way for organizations to conduct recurring audits to validate the security model and operational controls over time, not just once.

After signing an NDA, your company’s IT/security specialists can be granted access to conduct an audit according to an agreed schedule. We run open audit windows approximately twice per year to streamline planning across multiple customers.

Next open audit day: 15 July.

Audit scope and access level are defined per engagement (e.g., architecture review, key management flows, logging/integrity verification, and deployment controls).
Core51 app screenshot