Protecting your transport data and transactions.
At CoreFare, we process thousands of daily mobility transactions, making security the bedrock of our platform. We deploy a multi-layered security architecture designed to protect passenger data, secure payment flows, and ensure high availability for transport operators. Our practices align with industry standards and best practices for critical infrastructure.
Protecting the administrative side of transport operations is critical to preventing internal fraud and unauthorized access.
CoreFare does not directly process or store raw credit/debit card data. We tokenize all payment instruments via our PCI-DSS Level 1 certified payment gateway partners (such as Maya, GCash, and acquirer banks). Fare balances for closed-loop wallets are reconciled via double-entry accounting systems to detect and prevent balance manipulation.
We value the expertise of the cybersecurity community. If you are a security researcher and believe you have discovered a vulnerability in the CoreFare platform, we ask that you disclose it to us responsibly.
Please email your findings to security@coretech.com.ph. We request that you do not publicly disclose the vulnerability until we have had a reasonable timeframe to investigate and patch the issue.
Protecting your transport data and transactions.
CoreFare is designed to securely manage critical transport operations, fare collection, and passenger mobility data. We employ advanced security protocols to ensure that every transaction, ticket, and piece of operational data remains confidential and tamper-proof.
Access to operational dashboards and passenger data is strictly controlled. We support role-based access control (RBAC), multi-factor authentication (MFA), and secure session management to prevent unauthorized access by personnel or external actors.
CoreFare integrates with PCI-DSS compliant payment gateways. We do not store full credit card numbers or sensitive payment authentication data on our servers. Closed-loop card transactions rely on secure, encrypted NFC and smart card protocols.
In the unlikely event of a security incident, our dedicated incident response team is prepared to act swiftly. We have established protocols for containment, investigation, and transparent communication with affected operators and regulatory bodies.
We welcome reports from security researchers and the community. If you believe you have found a security vulnerability in CoreFare, please report it immediately to info@coretech.com.ph.