Security and trust
Security claims should be reviewable.
This page distinguishes safeguards verified for the public website from product controls that must be confirmed for a particular release, deployment, and customer agreement.
Public website safeguards
- HTTPS is required in production, with transport, content-type, framing, referrer, permissions, and content-security headers configured at the hosting layer.
- Optional analytics and advertising scripts remain off until an affirmative category choice; Global Privacy Control keeps them off.
- Contact and privacy-request APIs restrict origins and methods, cap request sizes, validate inputs, rate-limit abuse, suppress sensitive values from URLs, and return no-store responses.
- Website dependencies are checked for known high and critical vulnerabilities in release review, and source pipelines include static analysis and secret detection.
- A public security.txt provides the current reporting route.
Product security is deployment-specific
Cortrova product security depends on the contracted release, identity provider, hosting model, enabled integrations, customer configuration, data classification, operational ownership, and acceptance tests. Before production use, the written security schedule should identify authentication and MFA requirements, authorization roles, encryption and key management, audit events, backup and recovery, logging and monitoring, vulnerability response, incident notification, retention and deletion, subprocessors, network boundaries, and any AI model provider.
No certification by implication
Cortrova does not claim on this website to be FedRAMP authorized, SOC 2 certified, CMMC assessed, ISO certified, an ITAR registrant, or approved by a regulator. A feature that helps a customer maintain evidence or implement a control does not certify the customer, the software, or the deployment. Current assessment reports, registrations, attestations, and control evidence—if applicable—must be requested and verified for the exact service and date.
Regulated or sensitive data
Do not place CUI, export-controlled technical data, classified information, health data, payment credentials, government identifiers, or other regulated or sensitive information into this public website. A product deployment may process only the categories expressly authorized by the written scope after required contractual, technical, and operational controls are active and tested.
Report a security issue
Email contact@viceroynm.com with “Cortrova security report” in the subject. Include the affected URL or component, reproduction steps, potential impact, and a safe contact method. Do not access or alter other users’ data, disrupt service, use social engineering, or publicly disclose an unresolved issue. We will acknowledge legitimate reports and coordinate validation and remediation.