Cortex
CortexSecurity & Trust

Know the boundary. Prove the control.

Review how provider requests, Cortex telemetry, deployment choices, access controls, retention, and assurance evidence fit together before Cortex connects to your environment.

Two-path architecture

Provider traffic and Cortex telemetry are different paths.

On a standard provider request path, the selected model provider receives the prompt required to fulfill the request. Cortex telemetry synchronization is a separate path with its own capture, minimization, deployment, retention, and access boundary.

Provider request path

Selected model route

User or agent sends work

The selected client prepares the request for the chosen model provider.

Configured route applies

Pinned traffic keeps its provider. A configured managed route can apply the controls documented for that path.

Model provider fulfills it

The provider receives the prompt and context required to return the requested response.

Cortex telemetry path

Configured evidence boundary

01

Supported activity is captured

Device, provider, model, process, harness, and tool signals depend on the deployed capture path.

02

Capture data is minimized

Local capture policy minimizes the telemetry written and prepared for synchronization.

03

Telemetry sync follows policy

Approved telemetry synchronizes to the configured Cortex data plane under the deployment's retention and access controls.

Security boundaries

Four boundaries to verify before deployment.

Capture-side minimization

Supported device capture applies local policy before telemetry is written or prepared for synchronization. This is separate from provider-request handling.

Named network boundary

The local capture proxy listens on loopback. Managed routing or interception controls are documented separately for the configured deployment path.

Policy-controlled sync

Approved Cortex telemetry synchronizes to the configured data plane under the deployment's capture, access, retention, and deletion policy.

Access-scoped evidence

Cortex access controls scope who can review synchronized evidence. Source-system permissions and integration behavior remain part of the documented boundary.

Deployment

Deploy Cortex in the environment you control.

Choose the control boundary that matches your architecture, then verify the data handling, integration, access, and operational prerequisites.

Default enterprise POC

Cortex Cloud

Managed Cortex services with data handling defined by the selected service, region, and retention configuration.

Data livesDocumented Cortex environment

Customer Data Plane

Cortex telemetry is processed and stored in the customer-controlled cloud environment defined by the deployment architecture.

Data livesYour warehouse · VPC

Customer Hosted

Customer-operated deployment subject to architecture review, supported infrastructure, and integration requirements.

Data livesYour own infrastructure
Reads your data in place
SnowflakeDatabricksPostgres
Current architecture, assurance, and deployment documentation is provided during the security review.
Assurance

Evidence for the review you are running now.

Available reports and certifications can change. Cortex provides the current package, scope, and applicability directly to your security and procurement team.

Architecture and data-flow documentation
Identity and access-control overview
Retention and deletion controls
Subprocessor and deployment information
Current assurance reports, when applicable
Security questionnaire support
Procurement FAQ

The questions security teams ask first.

It depends on the configured route. On a standard provider request path, the selected provider receives the prompt required to fulfill the request. Cortex telemetry is a separate path. Managed enforcement applies only when the request or execution traverses a documented Cortex-controlled decision point.

The model provider receives the request content required for the selected AI workflow. Separately, approved Cortex telemetry synchronizes according to the deployed capture, minimization, destination, retention, and access policy.

The answer depends on the selected deployment. Cortex Cloud, a customer data plane, and customer-hosted options have different infrastructure and operational boundaries. The architecture review documents the applicable storage, processing, and integration path.

Cortex access controls scope who can review synchronized evidence. Source-system permissions, identity-provider configuration, tenant isolation, service identities, and administrative access are reviewed as separate controls for the selected deployment.

Cortex can provide current architecture and data-flow documentation, identity and access information, retention and deletion controls, subprocessor information, applicable assurance reports, and security-questionnaire support. The package is confirmed for scope and currency during the review.

Bring the boundary into your security review.

Review the current architecture, data flows, deployment model, access controls, retention, and applicable assurance evidence with the Cortex team.