Cortex AI OS
Build & orchestrate
Platform overviewThe 8-gate runtime and full capability map.Agent StudioNo-code agents from the skill catalog + role packs.Automation & WorkflowsVisual workflows, event automations, schedules.OntologyBusiness objects with property-level permissions.Model OpsMulti-provider routing, quotas, BYO local models.
Govern & prove
Control TowerPause, gate, and kill agent activity in real time.Agent IAMAgents as governed enterprise identities.Action FabricDry-run, approve, execute, compensate — on ledger.Policy-as-CodeTestable rules with simulate-before-ship.OversightFive autonomy modes with audited break-glass.Trust LedgerTamper-evident audit, signed receipts, provenance.Cost GovernanceBudgets with hard caps that fail closed.ObservabilityTraces, run quality, and reliability scores.
Connect
Integrations107-connector catalog, OpenAPI import, generic REST.MCP GatewayAllowlists, DLP, rate limits, kill switch.Architecture~22 services, one governed event backbone.
Financial ServicesFINRA-aware agents with full provenance.TaxThe 1040 pipeline with a published accuracy SLA.InsuranceClaims intake, fraud triage, payout approvals.Banking & KYC/AMLGoverned identity & sanctions review.HealthcareHIPAA-aligned agents with oversight.Public SectorAuditable AI for regulated agencies.Security OperationsDetection & response over agent activity.Energy & UtilitiesField and grid operations with approvals.TelecomNetwork and service ops, governed.Retail & E-commerceGoverned refunds, locked payment data.EducationFERPA-shaped permissions, human-approved aid.ManufacturingGated POs; OT locked away from every model.All industriesTwelve verticals on one governed runtime.
By industry
Financial ServicesWealth & retirement suite, FINRA-aware.InsuranceClaims, fraud triage, gated payouts.HealthcareHIPAA-aligned agents with oversight.Retail & E-commerceGoverned refunds, locked payment data.EducationFERPA-shaped permissions, cited answers.All industriesTwelve verticals on one runtime.
By role
Customer ServicePolicy-grounded answers, gated refunds.SalesQualified leads, CRM kept honest.IT Service DeskRunbook-only remediations, gated access.Finance OperationsRecon assist; payments stay human.Risk & ComplianceEvidence with provenance, on demand.All rolesEleven enterprise role packs.
Overview & packs
Solutions overviewBy industry and by role, on one runtime.Solution PacksSigned, portable governed agent bundles.US Individual Tax4-agent 1040 pipeline, published SLA.Claims AutomationEnd-to-end claims with approval gates.KYC/AML ReviewIdentity & risk review with provenance.
DocsStart here: concepts, guides, and the API.BlogGovernance engineering, in practice.GlossaryThe agent-governance vocabulary, defined.ChangelogWhat shipped, release by release.Trust CenterData handling, SLAs, residency, subprocessors.ComplianceEU AI Act, NIST AI RMF, ISO 42001 alignment.SecurityThe agent threat model and the 8 gates.AboutWhy we're building the AI operating system.
Agent LibraryCustomersPricing
Sign inRequest access
Platform
Platform overviewAgent StudioAutomation & WorkflowsOntologyModel OpsControl TowerAgent IAMAction FabricPolicy-as-CodeOversightTrust LedgerCost GovernanceObservabilityIntegrationsMCP GatewayArchitecture
Industries
Financial ServicesTaxInsuranceBanking & KYC/AMLHealthcarePublic SectorSecurity OperationsEnergy & UtilitiesTelecomRetail & E-commerceEducationManufacturingAll industries
Solutions
Financial ServicesInsuranceHealthcareRetail & E-commerceEducationAll industriesCustomer ServiceSalesIT Service DeskFinance OperationsRisk & ComplianceAll rolesSolutions overviewSolution PacksUS Individual TaxClaims AutomationKYC/AML Review
Resources
DocsBlogGlossaryChangelogTrust CenterComplianceSecurityAbout
More
Agent LibraryCustomersPricing
Sign inRequest access
Legal
Privacy PolicyTerms of ServiceData Processing AgreementSubprocessor Register

Legal

Privacy Policy

Last updated July 14, 2026

This policy explains what personal data Cortex AI OS processes, why, and the rights you have over it. It covers this website and the Cortex platform; where you use Cortex through your employer, your employer is the data controller and this policy supplements their notices.

01What we collect

  • Account data — name, work email, role, and authentication identifiers when you sign up or your organization provisions you.
  • Platform content — the prompts, documents, configurations, and run outputs your organization processes through its tenant. This data belongs to your organization.
  • Usage & device data — pages visited, features used, browser and device metadata, collected to operate and improve the service.
  • Contact data — anything you send through our demo, contact, or support channels.

02How we use it

We use personal data to operate the platform (authentication, tenancy, support), to secure it (audit trails, anomaly detection, abuse prevention), to bill for it, and to communicate with you about the service. Marketing communication is opt-in and separately unsubscribable.

03We do not train models on your data

Customer prompts, documents, and run outputs are never used to train machine-learning models — ours or anyone else's — on any plan. Model providers we route to are bound to the same restriction through their enterprise terms.

04Legal bases

Where GDPR or similar laws apply, we process personal data to perform our contract with you or your organization, to meet legal obligations, and under legitimate interests in securing and improving the service. Where consent is the basis (e.g. marketing), you can withdraw it at any time.

05Sharing

We share personal data only with the subprocessors listed in our Subprocessor Register (each under a data-processing agreement), with your organization's administrators, or where the law requires it. We do not sell personal data.

06Security & retention

Data is encrypted in transit and at rest; platform actions are recorded in a tamper-evident audit ledger. Account data is retained for the life of the account plus the period our legal obligations require; platform content follows your organization's configured retention. Business-plan tenants can set custom retention and residency.

07Your rights

Depending on your jurisdiction you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. Requests go to privacy@cortexaios.com; where your employer is the controller we will route the request to them.

08Contact

Privacy questions and requests: privacy@cortexaios.com.

Questions about this document: legal@cortexaios.com · See also the Trust Center

Cortex AI OS

The operating system for governed AI agents — every run gated, every decision provable.

Platform

Agent StudioAutomation & WorkflowsOntologyControl TowerAgent IAMTrust LedgerIntegrationsArchitectureView all capabilities →

Solutions

Solutions overviewAgent LibraryIndustriesFinancial ServicesTaxInsuranceBanking & KYC/AMLHealthcareSolution Packs

Trust

SecurityTrust CenterComplianceEU AI ActNIST AI RMFISO 42001SOC 2

Resources

DocsBlogChangelogGlossary

Company

AboutCareersCustomersPricingContactRequest access

Disclaimer: Cortex AI OS aligns its controls with the regulatory frameworks referenced across this site; alignment is not a certification or a legal guarantee of compliance. Company names, logos, and outcomes shown are illustrative unless explicitly identified as a customer. Product capabilities described reflect the current release and may evolve.

© 2026 Cortex AI OS
PrivacyTermsDPASubprocessors