trust

Built for your audit. Honest about ours.

How we engineer sovereignty, where our own compliance stands today, and how to reach us.

sovereignty

Your data. Your model. Your mission.

The AI in Corticle is yours: trained on your data, learning your playbooks, isolated to your tenant, used only for you.

  • No external models or APIs

    Nothing leaves your environment. Not for training. Not for inference. Not for telemetry. The platform makes zero external API calls to ours or anyone else's models in production.

  • Trained on your data

    Your model continuously learns from your playbooks, runbooks, procedures, and historical decisions. It operates the way your team operates, not a generic vendor playbook.

  • Isolated to your tenant, yours alone

    The intelligence trained on your data is isolated to your tenant. Never pooled with other customers. Never shared. Never used to train anyone else's model.

  • Deploy anywhere, same sovereignty

    On-prem, in your cloud (AWS · Azure · GCP), or air-gapped. The deployment topology changes; your data isolation and tenant boundary do not.

  • Used only for your mission

    We never use your data, your decisions, or your trained intelligence for anything else. Not for shared training pools. Not for product analytics. Not for benchmarking. Only your mission, full stop.

certification status

Engineered against ten frameworks. Honest about where each stands.

Our own certifications are in progress. Here's exactly where we are.

frameworkcustomer enablementcorticle's own status
SOC 2 Type IISupportedcontrols in place · audit planned
HIPAASupportedengineered against · BAA-ready
CMMCSupportedengineered to controls
FedRAMPSupportedauthorization on roadmap
NIST CSF 2.0Supported · 128 controls · 556 cross-framework mappingsengineered against
PCI DSSSupportedengineered to controls
ISO 27001Plannedengineered to controls
CJISPlannedengineered to controls
IRAPPlannedengineered to controls
StateRAMPPlannedengineered to controls

Status labels reflect Corticle's current attestation pipeline. We update them as audits progress.

sub-processors

None on the platform side.

The Corticle platform sends nothing to third-party services in production: no external model calls, no telemetry. It talks only to the security tools you connect, inside your environment — your data and your model never leave it.

The Corticle public website uses two sub-processors, both website-side only:

  • Formspree processes demo-request form submissions. Each submission contains only the fields you enter (name, work email, company, role).
  • Fathom Analytics provides cookieless, aggregate website analytics. Fathom sets no cookies and stores no personal identifiers, and EU visitor traffic is processed on EU-owned infrastructure. Because nothing requires consent, this site shows no cookie banner.
privacy posture

Plain language about what we collect and what we don't.

Website: we collect form submissions (name, work email, company, role) when you book a demo. Website analytics run on Fathom, a cookieless service that collects no personal information — this site sets no cookies at all. See the Sub-processors section above and our Privacy Policy for the full breakdown.

Platform: the deployed platform processes only the data inside your environment. No telemetry leaves your environment to us. See the Sovereignty section above.

Full website privacy policy: /privacy.

security contact

Report a vulnerability.

Send the details to security@corticle.io. We acknowledge disclosures within five business days. Please don't publicly disclose until we've had a chance to investigate and remediate.

ready when you are

Walk through this in your environment.

We'll show you the sovereignty model running, not a slide about it.

Book a demo