Skip to content
PlatformModulesIndustriesSecurityPricingInsights

Security and trust

Security claims should be reviewable.

This page distinguishes safeguards verified for the public website from product controls that must be confirmed for a particular release, deployment, and customer agreement.

Public website safeguards

  • HTTPS is required in production, with transport, content-type, framing, referrer, permissions, and content-security headers configured at the hosting layer.
  • Identifier-free page-load aggregates retain only date, hour, broad device class, and country code, with no page path or visitor/session ID, and stop after rejection; raw IP and user-agent are not retained in aggregate storage. Detailed analytics and advertising remain opt-in. Global Privacy Control keeps all measurement off.
  • Contact and privacy-request APIs restrict origins and methods, cap request sizes, validate inputs, rate-limit abuse, suppress sensitive values from URLs, and return no-store responses.
  • Website dependencies are checked for known high and critical vulnerabilities in release review, and source pipelines include static analysis and secret detection.
  • A public security.txt provides the current reporting route.

Hosting and provider attestations

This website is served from Render behind Cloudflare. Safeguards configured at the hosting layer, including transport security, edge caching, and header enforcement, rely on those providers' controls. Render and Cloudflare each maintain their own independent security attestations, such as SOC 2 reports, which are carved out of our own representations: we do not restate or certify a provider's controls, and current provider attestations should be requested from the provider or from us as part of a security review. We track provider attestation status and expiry in an internal vendor register. The subprocessors behind this website, with a change-notice commitment and a data processing agreement available on request, are published at /subprocessors/.

Product security is deployment-specific

Cortrova product security depends on the contracted release, identity provider, hosting model, enabled integrations, customer configuration, data classification, operational ownership, and acceptance tests. Before production use, the written security schedule should identify authentication and MFA requirements, authorization roles, encryption and key management, audit events, backup and recovery, logging and monitoring, vulnerability response, incident notification, retention and deletion, subprocessors, network boundaries, and any AI model provider.

This public site does not claim that a Cortrova release implements attribute-based access control, cryptographic audit-log linkage, append-only storage, or complete tamper verification. Role and attribute rules, audit-event coverage, integrity controls, verification procedures, and negative tests must be identified and evidenced for the contracted release before a buyer relies on them.

Incident response

Trunnion AI maintains a documented process for suspected security and personal-data incidents affecting this website. Reports received through the security route below are preserved, triaged, assigned to the responsible security owner, contained, investigated, and escalated for legal and customer-notification review when applicable. Notification timing is determined from the affected data, people, jurisdictions, contracts, and applicable law; the underlying response plan and notice matrix are maintained internally.

AI model training

Customer data may be used to train or fine-tune AI models only within that customer's own tenant. We do not perform cross-tenant training: one customer's content, prompts, or outputs are never used to train models used for another customer or a general-purpose model. Tenant-scoped training is governed by the customer's written scope and can be declined or disabled there, and the training restrictions that bind any third-party model provider are confirmed in the written security schedule. How AI risk is owned and reviewed is published in the AI Governance Statement.

Attestation roadmap

Our target attestation framework for Cortrova is SOC 2 Type II. A readiness program is active now: control mapping against the SOC 2 trust services criteria, the release-pipeline gates described on this page, dependency and secret scanning in CI, and the documented privacy, consent, and disclosure controls verified on this website. We will publish the audit window on this page when the audit engagement is signed. Until an attestation exists, we claim none; interim evidence, including the written security schedule, pipeline configuration, and current control documentation, is available to buyers under NDA on request.

No certification by implication

Cortrova does not claim on this website to be FedRAMP authorized, SOC 2 certified, CMMC assessed, ISO certified, an ITAR registrant, or approved by a regulator. A feature that helps a customer maintain evidence or implement a control does not certify the customer, the software, or the deployment. Current assessment reports, registrations, attestations, and control evidence, if applicable, must be requested and verified for the exact service and date.

Regulated or sensitive data

Do not place CUI, export-controlled technical data, classified information, health data, payment credentials, government identifiers, or other regulated or sensitive information into this public website. A product deployment may process only the categories expressly authorized by the written scope after required contractual, technical, and operational controls are active and tested.

Report a security issue

Email security@trunnion.ai with “Cortrova security report” in the subject. Include the affected URL or component, reproduction steps, potential impact, and a safe contact method. Do not access or alter other users’ data, disrupt service, use social engineering, or publicly disclose an unresolved issue. We will acknowledge legitimate reports and coordinate validation and remediation.

Necessary technology is always active because it provides security and remembers this choice.