Compliance

Controls reviewers can check, not slides they have to trust

Security, privacy, ethics, and operations controls reviewers can check before clearance.

  • BSI C5
  • ISAE 3000
  • Cyber Essentials Plus
  • GDPR
  • EU AI Act
  • EU-U.S. Privacy Shield
  • HIPAA
  • ISO 27017
  • ISO 14971
  • DORA
  • ISO 27018
  • ISO 13485

Security

Data is encrypted with FIPS-compliant AES at rest and TLS 1.2+ in transit. Each customer gets its own encryption keys under strict key management. Access is role-based through Azure AD, with audit logging on privileged actions. Capacity is geo-distributed with automated failover, and DRATA keeps compliance monitoring current as the platform changes.

  • FIPS-compliant AES at rest, TLS 1.2+ in transit
  • Per-customer keys and key management
  • Azure AD roles plus full audit logging
  • Geo-distributed redundancy and automated failover
  • DRATA-backed compliance monitoring

Privacy

We collect what the workload needs and isolate customer data by default. Host in the EU with no forced cross-border transfer, or on-premises when your perimeter is the requirement. Subprocessors are limited to named partners that meet the same bar. Retention and deletion are documented, and customer data is not used to train general-purpose models.

  • Data minimization and tenant isolation by default
  • EU hosting or on-premises, without forced transfer
  • Named subprocessors available for review
  • Documented retention and deletion; no training on your data

Ethics

Corti builds AI to assist people in regulated work, with humans staying in control. Every feature goes through security checks before production. Where AI systems are evaluated for safety, Corti runs bias detection, explainability reviews, and clinical safety checks that apply. Employees, partners, and users can report concerns through an anonymous form reviewed by qualified staff.

  • Security review on every feature before it ships
  • Bias, explainability, and safety evaluations where they apply
  • Anonymous concern form for employees, partners, and users
Anonymous concern form

Operations

What ships is meant to be traceable. Audit trails, change logs, and version control cover the platform. Vulnerability scans and third-party pentests run on a regular cycle. If a region fails, live failover recovers traffic. Incidents follow a documented response plan with root-cause write-ups.

  • Audit trails, change logs, and version control
  • Regular vulnerability scans and third-party pentests
  • Live failover and automated recovery
  • Incident response with root-cause documentation

In the Trust Center. Policies, reports, and the current control inventory sit there so reviewers can check them without waiting on a slide deck.

Yes. Host in the EU with no forced cross-border transfer, or on-premises when your perimeter is the requirement. Subprocessors stay limited to named partners that meet the same bar.

No. Customer data is not used to train general-purpose models. Retention and deletion are documented for review.

Data is encrypted with FIPS-compliant AES at rest and TLS 1.2+ in transit. Each customer gets its own encryption keys under strict key management.

Employees, partners, and users can submit through the anonymous concern form. Qualified staff review submissions.

Questions about the controls?
Review them in the Trust Center

Live reports sit in the Trust Center. Start on Corti Labs, or talk to us about a deployment.