Cortex
CortexSecurity for the agentic enterprise

Secure AI work fromintent to action.

Cortex is the security control plane for AI work. Map the AI attack surface, govern supported request and execution paths, and preserve the evidence security teams need to investigate what happened.

  1. Discover
  2. Govern
  3. Enforce
  4. Investigate
AI attack-surface investigation

From observed path to defensible verdict.

Follow one incident from human intent through the agent, destination, policy decision, and evidence security teams need to act.

Illustrative SEC-318 · four security questions

What did this agent touch?

HumanDevice / processAgent / modelDestination / portSensitive dataControl / incident

Focus · AI agent

Release helper

Agent path under investigation

Direct connections

Follow the recorded path from Priya through the Release helper, its device, model, destinations, and sensitive asset.

  • Priya Nair initiated Release helper. Evidence source: Slack request evt-91a · 09:41:03 EDT. Evidence state: Recorded evidence.
  • PRIYA-MBP-14 ran Cursor session 8bc1. Evidence source: Process and socket telemetry. Evidence state: Process / socket telemetry.
  • Cursor session 8bc1 hosted Release helper. Evidence source: Cursor session 8bc1. Evidence state: Recorded evidence.
  • Release helper used Claude. Evidence source: Claude trace 6f2. Evidence state: Instrumented request.
  • Claude served at api.anthropic.com:443. Evidence source: Managed gateway trace · POST /v1/messages. Evidence state: Instrumented request.
  • Release helper accessed github.com:443. Evidence source: Application audit log · GET /repos/payments-api. Evidence state: Instrumented request.
  • Release helper read .env.production. Evidence source: GitHub application audit log · 09:41:18 EDT. Evidence state: Instrumented request.
  • Release helper attempted vendor-deploy:8443. Evidence source: Cortex-managed MCP execution trace · 09:41:22 EDT. Evidence state: Instrumented request.
  • POL-27 evaluated vendor-deploy:8443. Evidence source: Candidate policy · audit mode. Evidence state: Configured policy decision.
  • SEC-318 records outcome POL-27. Evidence source: Observed, not blocked. Evidence state: Configured policy decision.
  • SEC-318 records impact .env.production. Evidence source: Production credential file accessed. Evidence state: Recorded evidence.

Connection evidence

Which agent reached which destination and port

4 events3 connected apps2 accountable people19 seconds

Select a destination or source record to inspect its correlated evidence. Request bodies and secret values are excluded.

01 · 09:41:12Instrumented

Actor

Release helperCursor session 8bc1
Priya NairRequester

Destination

TLS / HTTPSPOST /v1/messages
approved

Approved provider request

Capture boundary: Instrumented provider path.

02 · 09:41:12Instrumented

Actor

Release helperCursor session 8bc1
Priya NairRequester

Destination

TLS / HTTPSGET /repos/payments-api/contents/release-notes.md
observed

Repository context read

Capture boundary: Instrumented application path.

03 · 09:41:18Instrumented

Actor

Release helperCursor session 8bc1
Priya NairRequester

Destination

TLS / HTTPSGET /repos/payments-api/contents/.env.production
sensitive

Sensitive asset accessed

Capture boundary: Instrumented application path.

04 · 09:41:22Instrumented

Actor

Release helperCortex-managed MCP
Priya NairRequester

Destination

HTTPS / MCP JSON-RPCtools/call vendor-deploy
Action requiredMaya Voss

POL-27 audit mode · observed, not blocked

Capture boundary: Instrumented Cortex-controlled execution path.

Agent accountability

A named requester, device, agent, model, and owner.

Priya initiated the Release helper from Cursor on PRIYA-MBP-14. Maya Voss owns the AppSec investigation and policy decision.

Control decision

POL-27 observed the unapproved MCP attempt.

The configured Cortex-controlled path was in audit mode, so the attempt was evidenced rather than blocked. Remove access or approve a documented exception.

Illustrative SEC-318 investigation. Each event identifies its evidence source and coverage boundary. Process and socket telemetry identifies the process, remote host, and port. HTTP method and redacted path are available only when a managed gateway, provider trace, or application log supplies them. MCP operation detail is shown only for a Cortex-managed execution trace. Unavailable coverage is not treated as absence of activity.

04 · Investigate

Reach the verdict first. Then follow the evidence.

Linked evidence gives the CISO the incident window, impact, root cause, affected applications and devices, control outcome, chronology, and supporting evidence in one defensible analysis.

Review the data boundary

Root cause analysis · SEC-318 · Evidence-linked lineage graph

Production secret access through an unapproved agent path

Incident date
August 1, 2026
Incident window
09:41:03–09:41:22 EDT
Elapsed time
19 seconds
Severity
High · Action required
VerdictAction required

Unapproved agent path reached a production secret.

Release helper accessed .env.production, then attempted vendor-deploy outside the approved MCP inventory. POL-27 was in audit mode, so the sequence was observed and evidenced, not blocked.

Root cause

An embedded instruction in release-notes.md redirected the Release helper to .env.production. Its available permissions allowed the read before the unapproved vendor-deploy attempt.

Contributing conditions
  • • POL-27 was audit-only, not enforce mode.
  • • Production-secret read access remained available.
  • • vendor-deploy had no approved MCP inventory record.
Impact
Production credential file accessed
Control outcome
Observed, not blocked
Data disposition
No exfiltration observed in recorded evidence
Decision required
Remove access or approve an exception
Known incident scope

Correlated identities, systems, assets, and controls

Evidence as of 09:41:22 EDT
People and accountability

Priya Nair · requester

Maya Voss · AppSec investigation owner

Applications touched

Slack · Cursor · GitHub

SlackCursorGitHub
Agent and model

Release helper · Claude

Cursor session 8bc1

Device

PRIYA-MBP-14

Managed macOS · compliant

Sensitive asset

payments-api / .env.production

GitHub private repository · production

Destination and control

vendor-deploy · unapproved MCP

POL-27 candidate · audit mode

Linked incident chronology

How Cortex reached this verdict across four events and 19 seconds

  1. 09:41:03

    Human intent

    Step 1

    Priya asks the Release helper to update stripe-node and run release checks.

    Priya NairSlack#releases
    Explore work attribution
  2. 09:41:12

    Agent context

    Step 2

    Claude reads release-notes.md in payments-api. An embedded instruction requests .env.production.

    CursorClaudeGitHub
    Review agent governance
  3. 09:41:18

    Sensitive read

    Step 3

    GitHub application audit evidence shows the agent accessed .env.production six seconds later.

    GitHubpayments-api
    Review security data
  4. 09:41:22

    Tool attempt

    Step 4

    vendor-deploy is outside the approved MCP server list. Priya remains accountable for the requested change; Maya investigates and owns the policy decision.

    Maya VossInvestigatesUnapproved MCP
    Review managed controls

Illustrative root cause analysis. Signals retain their stated coverage and confidence; absence of evidence is not proof of absence.

Governance & security

A security boundary your team can review.

Cortex separates provider traffic from Cortex telemetry and documents capture, configurable minimization, policy simulation, and managed action controls across governed paths.

  • Provider and telemetry paths documented separately
  • Configurable minimization on supported capture paths
  • Deployment-specific access and control review
Cortex
Your VPC / ON-PREM · Your keys
On-device proxySupported activity
MinimizationConfigured locally
Cortex tenantSelected deployment
Guardrail event

Sensitive credential pattern matched in a simulated policy check.

Would block
Security

Built for a precise security review.

Architecture, data-flow, access-control, and deployment materials are available for a scoped review.

Defensible control policy

Control policy tells reviewers which controls apply to each governed path, who owns them, and how exceptions are handled.

Reviewable data paths

Provider request traffic and Cortex telemetry are documented separately, including configurable minimization and sync boundaries.

Managed enforcement paths

Admission and MCP controls apply where Cortex manages the traffic path. Other activity can be observed without implying universal enforcement.

Review your AI attack surface.

Review AI activity, managed controls, enforcement boundaries, and the security architecture behind Cortex.