Trust center
Cortee is built on trust and transparency to protect your data. Here you’ll find how we secure it, and how we handle it.
Security controls
Last scanned 6 hours ago.
A person writes these controls and keeps them up to date. Agents check them against evidence. The mark on the right means that check passed. If you want to see detailed evidence for each security control, please contact us at security@cortee.ai. We may share it with you after a signed NDA.
AI Governance
Activity log
Every AI action is monitored and logged. The log stores the decision, the model, the performance, the anonymized organization, and whether the action was allowed. It does not store the note or the page.
AI disclosure
Generated documents always display that they were created using AI.
Encryption and key management
Encryption in transit
Data is encrypted with TLS 1.2 or newer on the way between a client and the application, between the application and the database, and between the application and the model provider. That stops the data from being read or changed while it is on the way.
Encryption at rest
Customer data in database tables and static attachments, and the backups of both, is encrypted at rest with keys managed in the account that runs the product. Those keys are not issued one per customer.
Key access restricted
Privileged access to those encryption keys is limited to authorized people, and only for the work that needs the key.
Encryption audit trail
Encryption operations are logged. The log covers key generation, key access, and administrative actions on critical production systems.
Password hashing
Clerk, the authentication provider, hashes customer passwords with bcrypt. Bcrypt is a one-way hash, and each hash has its own salt, so two identical passwords do not produce the same hash.
Access control and authentication
Organizations manage their users
Administrators of an organization add and remove that organization's users. After a person is removed, their token cannot be renewed. Tokens last 60 seconds, so access ends within 60 seconds, including a session that was already open.
Support access
Customer support can open a customer's content through impersonation, and only when that customer has asked them to resolve a specific issue. The impersonation is recorded in the audit log.
Incidents and recovery
Backups
Point-in-time recovery is available for database tables.
Infrastructure as code
Infrastructure is created from code. In a disaster it can be deployed again in a new location.
Disaster recovery plan
A disaster recovery plan says how critical systems keep running and how data is restored.
Breach notification
Within 72 hours after Cortee becomes aware of a security breach, the affected customer is notified. The incident is published on the security page under Updates.
Incident response plan
An incident response plan says how an incident is handled.
Post-incident review
After an incident, the review records what has to change so the same incident does not happen again.
Practiced recovery
Recovery and incident response are practiced.
Secure development
Infrastructure changes
Application code and infrastructure changes are kept apart. Infrastructure is planned, reviewed, and applied by a person. No AI system plans, reviews, or applies an infrastructure change.
Agents do not change infrastructure
Agents do not create infrastructure and do not change IAM policies, unless a person has defined the change and reviewed it.
Vulnerability audits
A vulnerability audit runs on every deploy and once a day. Dependencies are scanned automatically. The application is scanned by reviewing every change before it reaches production. Every finding is reviewed. A deploy cannot go out while the code has a vulnerability.
Reporting vulnerabilities
Anyone may report a vulnerability they have found by sending it to security@cortee.ai. Reports are processed manually. High and critical vulnerabilities are answered within a short time.
Secure coding training
Developers have to take OWASP secure coding training.
Network and infrastructure security
Abuse monitoring
Monitoring is in place to detect abusive behavior and attacks.
Malware detection
Customer-uploaded attachments are scanned for malware. An attachment cannot be viewed, downloaded, or modified until that threat assessment is done. Until then, no language model, no internal system, and no user can access the uploaded data.
Change management
Pre-production testing
Changes are tested in pre-production before they reach production.
Automated and agentic testing
Changes go through automated testing and agentic testing.
Environment segregation
Environments are segregated from each other. Production data is never copied into testing.
Human review
A change does not ship until a person has reviewed it.
Rollback
Every change can be rolled back.