RBAC
Role-based access control down to the document level, mirroring your identity provider — enforced at retrieval, not just at display.
Trust
Our security model starts with absence: we can't lose, leak, or be breached for what we never hold. Cortex runs inside your perimeter — your storage, your keys, your models, your audit trail.
Most AI security risk is architectural: your data leaves your network and lives with someone else. Cortex removes the exit. The platform, its index, and its memory deploy where your data already is — and in air-gapped mode it makes no outbound connections of any kind.
| Data | Where it lives | Who can reach it |
|---|---|---|
| Your documents, indexes, graph, memory | Your infrastructure, your keys | Your teams, under your RBAC — never DoozieSoft |
| Queries and model traffic | Your infrastructure → providers you choose | You, and only the model providers you route to |
| Audit logs | Your infrastructure, exportable to your SIEM | Your security team |
| Telemetry | Off by default; opt-in only | Nobody, unless you turn it on |
| Waitlist details (this site) | DoozieSoft inbox | The Cortex team — see the Privacy Policy |
Role-based access control down to the document level, mirroring your identity provider — enforced at retrieval, not just at display.
AES-256 at rest and TLS 1.3 in transit, with customer-managed keys supported end to end.
Every query, retrieval, and model call recorded immutably — exportable to your SIEM for retention and review.
Vault-backed credentials with automatic rotation and least-privilege service accounts.
Your content is never used for training — ours or anyone else's. It stays in your storage, full stop.
VPC, on-premise, or fully air-gapped. No phone-home, no telemetry without consent.
| Model | Network egress | Where models run | Best for |
|---|---|---|---|
| Cloud | Allowed, to providers you choose | Your cloud VPC + selected model APIs | Fastest time to value |
| Private cloud | Restricted to your tenancy | Your VPC, including self-hosted models | Regulated industries |
| On-premise | Your network policy applies | Your racks — local models via Ollama / vLLM | Data-sovereignty requirements |
| Air-gapped | None — zero outbound connections | Local only | Defense, government, critical infrastructure |
Cortex controls are designed around SOC 2, ISO 27001, and GDPR requirements — with evidence exports built in so your auditors get artifacts, not promises. Formal certifications are in progress and will be published here when complete.
Security researchers are welcome. Report findings to cortex@dooziesoft.com — we acknowledge within 72 hours, coordinate disclosure timelines with you, and keep good-faith research within scope safe from legal action. Please avoid accessing customer data, degrading service, or social engineering.
Security reviews
We'll walk your team through the architecture, controls, and deployment model — with your checklist on the table.
Request a Review Session