Cortex AI OS
Build & orchestrate
Platform overviewThe 8-gate runtime and full capability map.Agent StudioNo-code agents from the skill catalog + role packs.Automation & WorkflowsVisual workflows, event automations, schedules.OntologyBusiness objects with property-level permissions.Model OpsMulti-provider routing, quotas, BYO local models.
Govern & prove
Control TowerPause, gate, and kill agent activity in real time.Agent IAMAgents as governed enterprise identities.Action FabricDry-run, approve, execute, compensate — on ledger.Policy-as-CodeTestable rules with simulate-before-ship.OversightFive autonomy modes with audited break-glass.Trust LedgerTamper-evident audit, signed receipts, provenance.Cost GovernanceBudgets with hard caps that fail closed.ObservabilityTraces, run quality, and reliability scores.
Connect
Integrations107-connector catalog, OpenAPI import, generic REST.MCP GatewayAllowlists, DLP, rate limits, kill switch.Architecture~22 services, one governed event backbone.
Financial ServicesFINRA-aware agents with full provenance.TaxThe 1040 pipeline with a published accuracy SLA.InsuranceClaims intake, fraud triage, payout approvals.Banking & KYC/AMLGoverned identity & sanctions review.HealthcareHIPAA-aligned agents with oversight.Public SectorAuditable AI for regulated agencies.Security OperationsDetection & response over agent activity.Energy & UtilitiesField and grid operations with approvals.TelecomNetwork and service ops, governed.Retail & E-commerceGoverned refunds, locked payment data.EducationFERPA-shaped permissions, human-approved aid.ManufacturingGated POs; OT locked away from every model.All industriesTwelve verticals on one governed runtime.
By industry
Financial ServicesWealth & retirement suite, FINRA-aware.InsuranceClaims, fraud triage, gated payouts.HealthcareHIPAA-aligned agents with oversight.Retail & E-commerceGoverned refunds, locked payment data.EducationFERPA-shaped permissions, cited answers.All industriesTwelve verticals on one runtime.
By role
Customer ServicePolicy-grounded answers, gated refunds.SalesQualified leads, CRM kept honest.IT Service DeskRunbook-only remediations, gated access.Finance OperationsRecon assist; payments stay human.Risk & ComplianceEvidence with provenance, on demand.All rolesEleven enterprise role packs.
Overview & packs
Solutions overviewBy industry and by role, on one runtime.Solution PacksSigned, portable governed agent bundles.US Individual Tax4-agent 1040 pipeline, published SLA.Claims AutomationEnd-to-end claims with approval gates.KYC/AML ReviewIdentity & risk review with provenance.
DocsStart here: concepts, guides, and the API.BlogGovernance engineering, in practice.GlossaryThe agent-governance vocabulary, defined.ChangelogWhat shipped, release by release.Trust CenterData handling, SLAs, residency, subprocessors.ComplianceEU AI Act, NIST AI RMF, ISO 42001 alignment.SecurityThe agent threat model and the 8 gates.AboutWhy we're building the AI operating system.
Agent LibraryCustomersPricing
Sign inRequest access
Platform
Platform overviewAgent StudioAutomation & WorkflowsOntologyModel OpsControl TowerAgent IAMAction FabricPolicy-as-CodeOversightTrust LedgerCost GovernanceObservabilityIntegrationsMCP GatewayArchitecture
Industries
Financial ServicesTaxInsuranceBanking & KYC/AMLHealthcarePublic SectorSecurity OperationsEnergy & UtilitiesTelecomRetail & E-commerceEducationManufacturingAll industries
Solutions
Financial ServicesInsuranceHealthcareRetail & E-commerceEducationAll industriesCustomer ServiceSalesIT Service DeskFinance OperationsRisk & ComplianceAll rolesSolutions overviewSolution PacksUS Individual TaxClaims AutomationKYC/AML Review
Resources
DocsBlogGlossaryChangelogTrust CenterComplianceSecurityAbout
More
Agent LibraryCustomersPricing
Sign inRequest access
Legal
Privacy PolicyTerms of ServiceData Processing AgreementSubprocessor Register

Legal

Data Processing Agreement

Last updated July 14, 2026

This DPA applies where Cortex processes personal data on behalf of a customer as a processor under GDPR, UK GDPR, CCPA/CPRA, or similar laws. It forms part of the agreement between Cortex and the customer.

01Roles and scope

The customer is the controller (or a processor acting for one); Cortex is a processor. Processing is limited to providing the platform per the agreement and the customer's documented instructions — including the governance configurations the customer sets in-product.

02Processing instructions

Cortex processes personal data only on documented instructions, including for transfers, unless required by law (in which case Cortex informs the customer unless prohibited). In-product configuration — policies, retention, residency, connector scopes — constitutes an instruction.

03Confidentiality & personnel

Personnel with access to customer data are bound by confidentiality and access is least-privilege, logged, and reviewed. Production access is gated and recorded in the same audit infrastructure the product exposes.

04Security measures

Encryption in transit and at rest, per-tenant logical isolation keyed on (tenantId, id), property-level access controls, DLP screening on tool calls, tamper-evident audit ledger, continuous red-teaming of the runtime, and the fail-closed governance gate chain on every run.

05Subprocessors

The customer authorizes the subprocessors in the Subprocessor Register (/legal/subprocessors). Cortex gives 30 days' notice before adding one; the customer may object on reasonable data-protection grounds. Subprocessors are bound by terms no less protective than this DPA.

06No training

Neither Cortex nor its model subprocessors use customer personal data to train or improve models. Model calls are inference-only.

07Data subject requests & assistance

Cortex routes data-subject requests it receives to the customer and provides reasonable assistance — including the audit and provenance tooling — for DSARs, DPIAs, and consultations with authorities.

08Transfers

Where personal data leaves the EEA/UK, transfers rely on adequacy decisions or Standard Contractual Clauses. VPC and air-gapped deployments keep data inside the customer's chosen boundary.

09Breach notification, deletion, audit

Cortex notifies the customer without undue delay after becoming aware of a personal-data breach. On termination, data is deleted or returned per the agreement (default: 30-day export window). Customers may audit compliance via our documentation, third-party reports, and — for Business plans — the security-review concierge.

Questions about this document: legal@cortexaios.com · See also the Trust Center

Cortex AI OS

The operating system for governed AI agents — every run gated, every decision provable.

Platform

Agent StudioAutomation & WorkflowsOntologyControl TowerAgent IAMTrust LedgerIntegrationsArchitectureView all capabilities →

Solutions

Solutions overviewAgent LibraryIndustriesFinancial ServicesTaxInsuranceBanking & KYC/AMLHealthcareSolution Packs

Trust

SecurityTrust CenterComplianceEU AI ActNIST AI RMFISO 42001SOC 2

Resources

DocsBlogChangelogGlossary

Company

AboutCareersCustomersPricingContactRequest access

Disclaimer: Cortex AI OS aligns its controls with the regulatory frameworks referenced across this site; alignment is not a certification or a legal guarantee of compliance. Company names, logos, and outcomes shown are illustrative unless explicitly identified as a customer. Product capabilities described reflect the current release and may evolve.

© 2026 Cortex AI OS
PrivacyTermsDPASubprocessors