Trust & Compliance

Enterprise-grade trust. Built in, not bolted on.

Cortx is infrastructure for your most sensitive asset — the knowledge that makes your organisation distinctive. Security, compliance, and data sovereignty are foundational requirements here, not afterthoughts.

01 Certifications

Independent verification of foundational controls.

Information security

ISO 27001

The international standard for an information security management system — risk assessment, access controls, incident management, and continuous improvement of security practice.

Quality management

ISO 9001

The international standard for quality management — consistent delivery through documented processes, internal audits, and management review.

Cyber hygiene

Cyber Essentials

The UK government-backed baseline across five technical controls: firewalls, secure configuration, access control, malware protection, and patch management.

Independently tested

Cyber Essentials Plus

Cyber Essentials with hands-on verification by an accredited assessor — vulnerability scans, simulated phishing, and checks of the security configuration in practice.

02 Security posture

How we protect your institutional knowledge.

The architecture starts from one principle: your institutional expertise is your most sensitive asset, and it is treated that way.

  • Encrypted at rest and in transit.
  • Role-based access control with comprehensive audit logging.
  • Knowledge sovereignty — your data stays under your governance at all times.
  • No training on customer data — your knowledge is never used to train AI models.
  • Hosted on enterprise-grade cloud infrastructure with appropriate certifications.
  • Regular penetration testing and security assessment.
03 Data sovereignty

Your knowledge. Your sovereignty.

Cortx keeps your institutional expertise under your governance — deployed where you choose, retracted when needed, and never used to train third-party models. For sovereignty-sensitive organisations, Cortx supports tenant-isolated deployment.

You decide what knowledge is captured, where it deploys, and who has access — and you can retract it at any time. That is not a feature; it is a foundational architectural decision.

Questions about security or compliance?

We are happy to walk procurement, security, and compliance teams through our posture and deployment options.