← Back to home
Security & privacy

Your data stays
yours.

Encrypted at rest, zero training on your content, GDPR-compliant, SOC 2 in progress. Bring your own API keys, or self-host the whole stack — Cortex is open core.

getcortex.org/security
Security posture
All green
Encryption at rest
AES-256
Transport
TLS 1.3
SOC 2 Type II
In progress
Data residency
EU (Frankfurt)
Self-host available. Run every component on your infra: Postgres, MinIO, MeiliSearch, Ollama.

Encrypted storage, per-team scoping, audit logs, full self-host option.

Why it matters

Zero training on your data

Your content is never used to train any model — ours or a third party's. Contractual with all AI providers we use.

Self-host the whole stack

Every component runs on your infra — Postgres, MinIO, MeiliSearch, Ollama for local LLMs. Fully air-gapped deployments supported.

Encrypted at rest + in transit

AES-256 at rest, TLS 1.3 in transit. Per-team encryption keys are on the roadmap for Q3.

GDPR, SOC 2, HIPAA-ready

GDPR-compliant today. SOC 2 Type II audit in progress. HIPAA available with self-hosted deployments and a signed BAA.

How it works

01

Choose hosting

Managed EU cloud, managed US cloud, or self-hosted. Data residency is guaranteed and verifiable.

02

Connect securely

All OAuth scopes are minimum-needed. API keys encrypted with a per-team envelope key.

03

Audit + export

Full audit log of every read and write. Export everything to JSON or Parquet at any time. No lock-in.

Who uses this

Built for people who actually ship work

ConsultantsAgenciesDevelopersProduct OwnersFreelancers

Questions, answered

Still curious? Write to us.

· Apply for early access ·

Hand every AI your memory.

Private beta. Limited spots. Redeem your code to jump in — or join the waitlist at the bottom of the page.