Trust

Security.

Our security model starts with absence: we can't lose, leak, or be breached for what we never hold. Cortex runs inside your perimeter — your storage, your keys, your models, your audit trail.

Vulnerability reports: cortex@dooziesoft.com · acknowledged within 72 hours

The principle

Most AI security risk is architectural: your data leaves your network and lives with someone else. Cortex removes the exit. The platform, its index, and its memory deploy where your data already is — and in air-gapped mode it makes no outbound connections of any kind.

What we hold vs. what stays yours

Data held by DoozieSoft versus data that stays on customer infrastructure
Data Where it lives Who can reach it
Your documents, indexes, graph, memory Your infrastructure, your keys Your teams, under your RBAC — never DoozieSoft
Queries and model traffic Your infrastructure → providers you choose You, and only the model providers you route to
Audit logs Your infrastructure, exportable to your SIEM Your security team
Telemetry Off by default; opt-in only Nobody, unless you turn it on
Waitlist details (this site) DoozieSoft inbox The Cortex team — see the Privacy Policy

Platform controls

RBAC

Role-based access control down to the document level, mirroring your identity provider — enforced at retrieval, not just at display.

Encryption

AES-256 at rest and TLS 1.3 in transit, with customer-managed keys supported end to end.

Audit logs

Every query, retrieval, and model call recorded immutably — exportable to your SIEM for retention and review.

Secrets management

Vault-backed credentials with automatic rotation and least-privilege service accounts.

Customer-owned data

Your content is never used for training — ours or anyone else's. It stays in your storage, full stop.

Private deployment

VPC, on-premise, or fully air-gapped. No phone-home, no telemetry without consent.

Deployment matrix

Comparison of Cortex deployment models
Model Network egress Where models run Best for
Cloud Allowed, to providers you choose Your cloud VPC + selected model APIs Fastest time to value
Private cloud Restricted to your tenancy Your VPC, including self-hosted models Regulated industries
On-premise Your network policy applies Your racks — local models via Ollama / vLLM Data-sovereignty requirements
Air-gapped None — zero outbound connections Local only Defense, government, critical infrastructure

Compliance posture

Cortex controls are designed around SOC 2, ISO 27001, and GDPR requirements — with evidence exports built in so your auditors get artifacts, not promises. Formal certifications are in progress and will be published here when complete.

  • SOC 2-aligned controls
  • ISO 27001-ready
  • GDPR-conscious design

Vulnerability disclosure

Security researchers are welcome. Report findings to cortex@dooziesoft.com — we acknowledge within 72 hours, coordinate disclosure timelines with you, and keep good-faith research within scope safe from legal action. Please avoid accessing customer data, degrading service, or social engineering.

Security reviews

Running a security review? Let's talk.

We'll walk your team through the architecture, controls, and deployment model — with your checklist on the table.

Request a Review Session