SECURITY & TRUST

Security is part of the information model.

CORIIO connects information without erasing the boundaries that make it trustworthy. Identity, organization, source permission, purpose, policy and audit remain present from ingestion through answer and action.

IdentityOrganizationSource ACLPolicy
Authorized evidence set
RetrievalReasoningDecisionAction
01

Tenant isolation

Every request carries an organization context. Storage, retrieval, execution and audit queries are scoped to that organization, with negative integration tests for cross-tenant access.

02

Control plane / data plane

The platform control plane manages release and lifecycle operations. Customer data planes own content, connector credentials, indexes, evidence, policies and operational logs.

03

Source permission preservation

Connectors ingest available ACL context. Retrieval filters inaccessible evidence before ranking or model invocation; permission revocation and source deletion are lifecycle events.

04

Identity and lifecycle

SSO and SCIM contracts support enterprise identity and account lifecycle. Authentication establishes identity; RBAC, attributes, organization policy and source permissions determine authorization.

05

Privileged and support access

Administrative operations use explicit scopes and audit records. Support access is not an implicit bypass; it requires a controlled path, bounded purpose and traceable activity.

06

Encryption and secrets

Network connections require TLS. Credentials remain server-side and are stored through environment or secret-management boundaries, never rendered into the client application.

07

Audit and evidence

Queries, decisions, reviews, workflow transitions, tool calls and privileged changes retain actors, organization, correlation identifiers and relevant evidence references.

08

AI governance

Provider abstraction, evaluation gates, model routing policy and grounded-generation rules separate model capability from application authority. Models cannot invent permissions or approve their own consequential actions.

09

Prompt injection

Retrieved text is treated as untrusted evidence, not executable instruction. Tool grants, source policy and action approval remain outside retrieved content and model output.

10

Privacy and retention

Classification, minimization, purpose, retention, deletion and legal-hold controls apply across ingestion, indexes, evidence and generated artifacts.

11

Incident response

Detection, triage, containment, evidence preservation, recovery and corrective-action ownership are defined as operational workflows; public claims do not exceed tested evidence.

12

Recovery

Idempotent operations, bounded retry, backup/restore contracts and degraded modes are designed to preserve authorization, provenance and integrity during failure.

CLAIMS BOUNDARY

What this page does—and does not—claim.

This page describes implemented architecture and target enterprise contracts. It does not claim SOC 2, ISO 27001, HIPAA, FedRAMP or another certification. Formal attestations, external penetration testing and customer-specific control evidence are shared only when they exist and are appropriate for the review.