Regulatory support
Software can support controls. It cannot confer compliance.
Cortrova can be evaluated for workflows related to quality, safety, export control, cybersecurity, environmental, financial, and electronic-record requirements. Applicability and conformance must be established for each customer and deployment.
Frameworks customers may ask us to evaluate
Examples include ISO 9001 and 14001, AS9100, IATF 16949, FDA electronic-record requirements, OSHA and EPA recordkeeping, ITAR and export-control obligations, CMMC and DFARS requirements, FAR contract clauses, and cost-accounting requirements. Listing a framework identifies a potential requirements-mapping exercise; it is not a claim of certification, registration, authorization, assessment, legal compliance, or guaranteed suitability.
Production-readiness process
- Applicability: the customer and qualified advisers identify the laws, contracts, standards, data types, jurisdictions, and responsible owners.
- Requirements: the written scope maps applicable requirements to product behavior, customer procedures, integrations, evidence, and controls outside Cortrova.
- Configuration: roles, approvals, retention, records, integrations, AI permissions, and deployment boundaries are configured for the approved use.
- Validation: the parties test representative positive, negative, permission, retention, recovery, audit, and human-oversight scenarios against acceptance criteria.
- Evidence: approved configurations, versions, test results, exceptions, training, changes, and owners are retained and reviewed on a schedule.
Shared responsibility
Viceroy is responsible for the commitments in the applicable agreement. The customer remains responsible for its legal and regulatory analysis, policies, workforce training, data classification, identity administration, device and network controls, configured use, human decisions, records, incident response, filings, certifications, registrations, and auditor or regulator communications unless a signed agreement expressly allocates a task otherwise.
AI-assisted workflows
AI output must not be treated as a compliance determination. Regulated or material actions require the review and approval assigned in the customer’s procedure. Model access, data routing, retention, training restrictions, logging, evaluation, correction, escalation, and disablement must be confirmed before production use. See the AI Transparency Notice.
Request evidence for the exact deployment
Ask for a dated capability matrix, architecture and data-flow description, subprocessor list, security schedule, requirements traceability, test plan, exception register, and acceptance evidence for the release and environment you will use. Product pages are not substitutes for those materials or for advice from qualified legal, regulatory, quality, accounting, export-control, or cybersecurity professionals.