Cortex
Cortex / Platform

One loop, from capture to owned.

Atlas connects supported AI activity to work and cost context. Foundry routes configured requests, supports evaluation, and builds datasets and models within the selected deployment boundary.

Security controls need context before the decision point. Cortex connects supported device and gateway signals to the Work Graph and managed request paths.

Capture coverage depends on deployed integrations. Where Cortex manages a request path, identity and Work Graph context can inform a policy decision and produce evidence for review.

The loop, mapped to products

Capture → Enrich → Route → Train → Own.

Atlas, capture & understand
Foundry, route & train
You, own the result
01

Capture

On-device sensor and local proxy record supported provider, harness, and tool signals.

02

Enrich

Turns become Work Units, Streams, and a living context graph.

03

Route

Configured requests take their selected value path, enriched with the context available for that route.

04

Train

Repeated work becomes labeled corpora for models specialized to you.

05

Own

Context and model artifacts follow the configured ownership and hosting boundary.

Each loop makes the next one cheaper and better
Security control plane

Context before control. Evidence after action.

Cortex connects what it knows about work to policy and managed control points. Enforcement applies only where traffic follows a supported path.

01 / Context

Work Graph context

Relate a request to an actor, agent, model, tool, project, and observed work.

02 / Decide

policy evaluation

Compare identity and request context with the policy configured for that path.

03 / Control

managed enforcement point

Admit, deny, or constrain the request where Cortex manages the traffic path.

04 / Record

decision receipt

Record the policy context and resulting decision for supported control events.

05 / Investigate

investigation evidence

Use linked activity and decisions to reconstruct what Cortex observed.

Architecture

Edge → Core → Access.

Supported device telemetry can synchronize to the configured data plane. The architecture separates capture, provider traffic, and Cortex telemetry so reviewers can inspect each boundary.

Edge

On the device

A sensor and local proxy can capture supported AI activity, with configurable minimization before telemetry sync.

  • On-device sensor
  • 127.0.0.1 proxy
  • Configurable minimization
Core

Your cloud / VPC

Normalize, cluster, label, and build the context graph and owned datasets, inside your boundary.

  • Cluster & label
  • Context graph
  • Owned datasets
Access

App & headless

People work in the app; agents read the same graph headlessly through the API and MCP.

  • In-app surfaces
  • API / MCP
  • Permission-scoped
The live map

A live map of how work actually moves.

Across supported tools, teams, and systems. Each line represents observed AI activity flowing into Cortex and back out as reusable Work Graph context.

Cortex
ChatGPT
Marketing
Claude
Engineering
Gemini
Research
Grok
Data
Copilot
Eng Platform
Perplexity
Strategy
Notion AI
Ops
Slack AI
Ops
Integrations

100+ tools, day one.

No new workflow. Cortex meets your teams in the tools they already use, and the models they already call.

IDEs & dev

Editors, CI, issue trackers and code hosts.

Chat & collab

Where conversations and decisions happen.

Model providers

Frontier, open and local models alike.

Data stores

Warehouses, lakes and document stores.

Why Cortex

Why not just use what you have?

Provider dashboards / usage consoles
See tokens and cost, per key, per model.
Observability / tracing
See what happened inside a single call.
FinOps tools / cloud cost
See the total bill, after the fact.
Cortex
Sees whether the work got done and its true cost, then turns it into context and models you own.

Traditional tools focus on spend or request telemetry. Cortex adds work and outcome context.

Security & Trust

Local capture. Reviewable deployment boundaries.

Cortex supports local capture and policy-controlled telemetry sync. Deployment boundaries, access controls, and available review materials are documented for security and procurement teams.

  • Supported on-device capture & configurable minimization
  • 127.0.0.1 proxy · policy-controlled sync
  • Deployment options · SSO/SAML · role-based access
See Security & Trust
Cortex · Data boundary
Captured on deviceminimized before synclocal
Sync under policyyou choose what & whengated
Stored in your VPCpermission-scoped accessyours

See the whole loop run on your own data.

We'll stand up Edge, Core and Access in your environment and walk the loop end to end, capture to owned.