
Last updated: June 2026
Every organisation that adopts Cortextual entrusts us with some of its most valuable business assets. Beyond data, organisations rely on our platform to help preserve institutional knowledge, understand organisational structures, support workforce planning, and enable artificial intelligence to operate with meaningful business context.
We recognise that this trust must be earned every day. It cannot be established solely through technology, legal documentation, or security controls. Trust is built through responsible product design, transparent governance, robust operational practices, and a continuous commitment to protecting the confidentiality, integrity, and availability of the information entrusted to us.
As organisations increasingly adopt artificial intelligence to support operational and strategic decision-making, security has become more than a technical consideration. It is a fundamental business requirement. Organisations need confidence that their information is handled responsibly, that access to sensitive knowledge remains appropriately controlled, and that AI systems operate within clearly defined governance frameworks.
Security is therefore not treated as a standalone feature of the Cortextual platform. It is one of the core principles on which the platform is designed, developed, operated, and continuously improved.
This Security & Trust Centre explains the principles that guide our approach to security, the measures we take to protect our platform and customer information, and the processes we have established to identify, manage, and respond to security-related matters. It also explains how security researchers and customers can responsibly report vulnerabilities or security concerns to our team.
At Cortextual, we view security as an ongoing commitment rather than a fixed destination. Cybersecurity continues to evolve rapidly alongside technological innovation, emerging threats, changing regulatory requirements, and increasing customer expectations. Maintaining an effective security programme therefore requires continuous assessment, adaptation, and improvement.
Our approach combines technical safeguards, organisational governance, operational procedures, and responsible product development. Rather than relying on any single security control, we seek to build multiple complementary layers of protection that together help reduce risk and strengthen the resilience of our platform.
Security is also closely connected to the way Cortextual has been designed. Our platform exists to help organisations organise and understand their own knowledge while maintaining appropriate control over it. This objective influences architectural decisions, access management, AI governance, and the way information is processed throughout the platform.
We recognise that every organisation operates within its own legal, regulatory, and operational environment. For that reason, we continuously review our security practices and seek to align them with recognised industry standards, evolving best practices, and the changing needs of our customers.
Although no technology platform can eliminate every possible security risk, our objective is straightforward: to operate Cortextual responsibly, transparently, and in a manner that enables organisations to use the platform with confidence.
Security considerations form part of the entire lifecycle of the Cortextual platform.
From the earliest stages of product planning, we seek to evaluate how new functionality, integrations, infrastructure changes, and AI capabilities may affect the security of the platform and the information processed through it. Identifying potential risks before functionality is introduced allows appropriate safeguards to be incorporated into the design wherever reasonably practicable.
Security continues to be considered throughout development, testing, deployment, and ongoing maintenance. As the platform evolves, we regularly review our architecture, development practices, operational procedures, and supporting infrastructure with the objective of strengthening resilience, improving reliability, and reducing unnecessary security risks.
This continuous approach enables security considerations to evolve alongside the platform itself. New technologies, customer requirements, regulatory developments, and emerging cybersecurity threats all contribute to the ongoing refinement of our security programme.
Where appropriate, we also seek to incorporate recognised security principles into our software development practices, including secure coding practices, appropriate testing, controlled deployment processes, vulnerability remediation, and regular maintenance of the technologies supporting the platform.
While security can never be considered complete, our objective is to ensure that it remains an integral part of every stage of the platform's evolution rather than a reactive measure implemented only after deployment.
Cortextual was built on a simple belief: organisational knowledge is one of the most valuable assets a business possesses.
Every organisation accumulates knowledge through its people, documents, communications, processes, policies, projects, and day-to-day operations. Preserving that knowledge is essential not only for operational efficiency but also for business continuity, compliance, effective onboarding, informed decision-making, and long-term organisational resilience.
Unlike many AI solutions that rely primarily on publicly available information or isolated datasets, Cortextual is designed to help organisations securely connect and understand the knowledge that already exists within their own business environment. The platform brings together organisational information from authorised sources, allowing users to interact with that knowledge while respecting the access permissions established by the organisation.
One of the guiding principles behind Cortextual is that organisations should remain in control of their own information. Wherever technically supported, the platform is designed to respect existing user permissions and access controls within connected systems. This permission-aware approach helps ensure that users can only access information they are already authorised to view, reducing unnecessary exposure of sensitive business information while preserving the integrity of existing governance structures.
As organisations increasingly integrate artificial intelligence into their operations, maintaining appropriate governance over organisational knowledge becomes increasingly important. Our objective is to enable AI to work with meaningful organisational context while continuing to respect the security, privacy, and access controls established by our customers.
Protecting organisational information is therefore not simply a technical requirement. It is a core design principle that influences how Cortextual is developed, how integrations operate, and how users interact with knowledge across the platform.
Effective security begins with ensuring that the right individuals have access to the right information at the right time.
Cortextual incorporates identity and access management mechanisms designed to help organisations manage user access in accordance with their internal governance requirements. Platform functionality is intended to be made available according to the permissions assigned to individual users and the responsibilities associated with their role within the organisation.
Where platform functionality relies upon information obtained from connected third-party services, Cortextual seeks to respect the permissions already configured within those systems wherever technically supported. This permission-aware architecture is intended to preserve existing access controls while enabling users to search and interact with organisational knowledge through the platform.
Internally, access to customer information and administrative systems is restricted to authorised personnel whose responsibilities require such access. Administrative privileges are granted in accordance with the principle of least privilege and are subject to appropriate governance, oversight, and operational controls.
We continue to review our authentication and access management practices as the platform evolves to support both organisational security and an effective user experience.
A secure platform depends upon a resilient and well-managed technical infrastructure. For that reason, Cortextual seeks to implement appropriate technical and organisational measures designed to protect the systems that support the availability, reliability, and security of our services.
Our infrastructure is designed with security, scalability, and operational resilience in mind. We continuously review our technical architecture to ensure that it remains appropriate for the services we provide, the nature of the information processed through the platform, and the evolving cybersecurity landscape.
Where appropriate, we implement safeguards intended to protect our infrastructure from unauthorised access, disruption, misuse, and other security threats. These safeguards may include secure network architecture, logical separation of environments, secure configuration management, vulnerability remediation, infrastructure monitoring, software maintenance, and controlled deployment procedures.
As our platform continues to evolve, we regularly assess our infrastructure against emerging technologies, recognised industry practices, and changing customer expectations. Infrastructure security is therefore regarded as an ongoing process of continuous improvement rather than a fixed technical configuration.
Protecting customer information throughout its lifecycle is one of the fundamental objectives of our security programme.
Where appropriate, Cortextual uses industry-recognised encryption technologies to help protect information while it is transmitted between users, connected services, and the platform. We also seek to implement appropriate safeguards designed to protect information stored within our systems and supporting infrastructure.
Encryption represents one component of a broader information security framework. It operates alongside authentication mechanisms, access controls, infrastructure security, operational monitoring, and organisational governance to help reduce the risk of unauthorised access, disclosure, alteration, or loss of information.
We recognise that effective information security requires more than technical controls alone. Accordingly, we continuously review our security architecture and technical safeguards to ensure they remain appropriate as technology, regulatory expectations, and cybersecurity threats continue to evolve.
Artificial intelligence sits at the core of the Cortextual platform. We recognise that AI systems introduce additional considerations relating to security, governance, transparency, and the responsible handling of organisational information.
Unlike general-purpose AI systems that generate responses without organisational context, Cortextual is designed to operate using authorised organisational knowledge while respecting the permissions established within connected systems wherever technically supported. This permission-aware approach is intended to ensure that users receive responses based on information they are already authorised to access rather than exposing information outside their existing permissions.
We also recognise that trust in AI depends upon transparency. Wherever applicable, Cortextual seeks to provide users with information regarding the origin of AI-generated responses, enabling users to understand how conclusions have been reached and to verify the underlying source material where appropriate.
Our approach to AI security extends beyond protecting data. It also includes responsible governance over how AI functionality is designed, implemented, and continuously improved. We regularly review AI-related risks, evaluate new technologies responsibly, and seek to ensure that our AI capabilities continue to operate in a manner consistent with our broader commitments to security, privacy, transparency, and responsible innovation.
Further information regarding our governance of artificial intelligence is available in our Responsible AI & AI Transparency document.
Cybersecurity is an ongoing discipline rather than a one-time implementation. New technologies, attack methods, regulatory developments, and customer expectations require organisations to continuously evaluate and strengthen their security posture.
Accordingly, Cortextual seeks to maintain appropriate visibility over the health and security of the platform through operational monitoring, system logging, and the continuous review of security-relevant events. These activities assist us in identifying potential issues, investigating unusual behaviour, maintaining platform stability, and supporting the effective operation of our services.
Monitoring also enables us to identify opportunities for improvement. We regularly assess our security controls, governance framework, operational procedures, and technical safeguards in light of operational experience, customer feedback, technological developments, and evolving industry practices.
Security is therefore viewed as a process of continuous enhancement. As the platform grows and new capabilities are introduced, we remain committed to reviewing and strengthening our security programme to ensure it continues to reflect the nature of our services and the expectations of our customers.
Many organisations rely on Cortextual to support critical business processes, preserve organisational knowledge, and enable informed decision-making. Maintaining the resilience and availability of the platform is therefore an important component of our overall security programme.
We seek to implement appropriate business continuity and operational resilience measures designed to support the continued operation of our services and to facilitate recovery in the event of significant operational disruption. These measures may include backup procedures, disaster recovery planning, operational response processes, infrastructure resilience, and other organisational and technical safeguards appropriate to the services we provide.
While no online service can guarantee uninterrupted availability under all circumstances, we continuously review our operational resilience measures and seek to improve our ability to respond effectively to unexpected events while minimising disruption to our customers.
Business continuity planning is reviewed alongside our broader security and operational governance framework to ensure that Cortextual continues to evolve as a reliable platform for organisations managing increasingly important operational knowledge and workforce information.
Despite robust preventive measures, no technology platform can entirely eliminate the possibility of security incidents. For that reason, Cortextual maintains processes designed to identify, assess, manage, and respond appropriately to potential security events affecting our platform or the information entrusted to us.
Where a security incident is identified, we seek to investigate the matter promptly, assess its nature and potential impact, contain and remediate the issue where appropriate, and implement measures intended to reduce the likelihood of similar incidents occurring in the future.
Where required by applicable law, contractual obligations, or the nature of the incident itself, we will communicate with affected customers and relevant authorities in accordance with our legal and regulatory obligations.
Incident response is an important component of our overall security programme and is continuously reviewed as part of our commitment to improving the resilience and security of the Cortextual platform.
We value the contribution of the security community in helping organisations identify and address potential vulnerabilities responsibly.
If you believe you have identified a security vulnerability affecting the Cortextual platform, we encourage you to report it to us promptly through the contact details provided below. We ask that any security research is conducted responsibly, in good faith, and in a manner that avoids disrupting our services, compromising customer information, or affecting other users of the platform.
When reporting a potential vulnerability, we encourage researchers to provide sufficient information to enable our team to understand, reproduce, and investigate the issue efficiently. This may include a description of the vulnerability, the affected functionality, steps to reproduce the issue where appropriate, and any supporting technical information.
We are committed to reviewing all legitimate security reports, investigating reported issues appropriately, and taking reasonable steps to remediate confirmed vulnerabilities. We also ask researchers to allow us a reasonable opportunity to investigate and address reported issues before publicly disclosing them.
Responsible and coordinated disclosure benefits both our customers and the wider security community, and we appreciate the efforts of researchers who help us strengthen the security of the Cortextual platform.
If you have any questions regarding the security of the Cortextual platform, wish to report a potential security vulnerability, or believe you have identified a security incident affecting our services, we encourage you to contact our Security Team.
Security Team
Email: security@cortextual.com
If your enquiry relates to the processing of personal information or the exercise of your privacy rights, please refer to our Privacy Notice or contact our Privacy Team using the details provided therein.
We aim to review all genuine security enquiries promptly and will respond as appropriate, taking into account the nature and complexity of the matter reported.
Security is not a milestone that can be achieved once and considered complete. It is an ongoing responsibility that evolves alongside our platform, our customers, and the technology landscape in which we operate.
As Cortextual continues to develop new capabilities, expand integrations, and support organisations navigating the transition to human and AI-powered workforces, we remain committed to strengthening our security practices, enhancing our governance framework, and continuously improving the way we protect our platform and customer information.
Our objective is simple: to build and operate a platform that organisations can trust—not only today, but as their business continues to evolve.