Tenant isolation
Every request carries an organization context. Storage, retrieval, execution and audit queries are scoped to that organization, with negative integration tests for cross-tenant access.
SECURITY & TRUST
CORIIO connects information without erasing the boundaries that make it trustworthy. Identity, organization, source permission, purpose, policy and audit remain present from ingestion through answer and action.
Every request carries an organization context. Storage, retrieval, execution and audit queries are scoped to that organization, with negative integration tests for cross-tenant access.
The platform control plane manages release and lifecycle operations. Customer data planes own content, connector credentials, indexes, evidence, policies and operational logs.
Connectors ingest available ACL context. Retrieval filters inaccessible evidence before ranking or model invocation; permission revocation and source deletion are lifecycle events.
SSO and SCIM contracts support enterprise identity and account lifecycle. Authentication establishes identity; RBAC, attributes, organization policy and source permissions determine authorization.
Administrative operations use explicit scopes and audit records. Support access is not an implicit bypass; it requires a controlled path, bounded purpose and traceable activity.
Network connections require TLS. Credentials remain server-side and are stored through environment or secret-management boundaries, never rendered into the client application.
Queries, decisions, reviews, workflow transitions, tool calls and privileged changes retain actors, organization, correlation identifiers and relevant evidence references.
Provider abstraction, evaluation gates, model routing policy and grounded-generation rules separate model capability from application authority. Models cannot invent permissions or approve their own consequential actions.
Retrieved text is treated as untrusted evidence, not executable instruction. Tool grants, source policy and action approval remain outside retrieved content and model output.
Classification, minimization, purpose, retention, deletion and legal-hold controls apply across ingestion, indexes, evidence and generated artifacts.
Detection, triage, containment, evidence preservation, recovery and corrective-action ownership are defined as operational workflows; public claims do not exceed tested evidence.
Idempotent operations, bounded retry, backup/restore contracts and degraded modes are designed to preserve authorization, provenance and integrity during failure.
CLAIMS BOUNDARY
This page describes implemented architecture and target enterprise contracts. It does not claim SOC 2, ISO 27001, HIPAA, FedRAMP or another certification. Formal attestations, external penetration testing and customer-specific control evidence are shared only when they exist and are appropriate for the review.