Skip to main content

Privacy at Falcon Cortex Intelligence

Understand the signal. Protect the person.

Cortex is designed to give organizations useful operational insight with clear limits on what the desktop may collect. This page explains the product design and where customer choices matter.

Current notice status

The public privacy notice remains a working draft for controlled UAT. Actual controller and processor roles, processing locations, retention and suppliers must be confirmed for each tenant before service access.

Read the draft notice

Three boundaries that shape the product

The tenant sets the scope

Capture modes, application exclusions, roles and retention require approved tenant policy and a lawful basis for the actual deployment.

Content is outside capture

The desktop design prohibits typed characters, raw key sequences, passwords, field values, clipboard content, screenshots and file content.

Authority before capture

The desktop legal flow presents the current notice after sign-in and requires a matching server receipt before capture is enabled.

The detail

What depends on your setup

Cortex has a public website, authenticated web administration and a desktop agent. The approved tenant agreement and configuration determine which service data is processed. The categories below describe possible data, not a statement that every feature is active for every customer.

What may be processed

  • Identity and access: business contact details, tenant, workspace, role and sign-in or device events needed to provide and secure access.
  • Operational context: approved task, application, time and process signals where a tenant enables capture under its policy.
  • Process information: records a tenant submits through an approved workflow or integration.
  • Support and service: information a requester chooses to send, plus safe diagnostic or correlation details needed to investigate a case.

Desktop capture boundaries

Standard Context and optional Precision Interaction are separate modes. Precision Interaction is designed for aggregate, bucketed, non-content signals. Tenant application and control exclusions, notice, lawful basis and privacy review are required governance inputs. A changed notice must be presented and acknowledged again before capture authority advances.

The desktop engineering baseline excludes typed text, raw key sequences, passwords, field values, clipboard contents, screenshots and file contents. Jurisdiction-specific counsel and each tenant's worker and privacy information still require approval before production distribution.

Control and lifecycle

An organization determines its service instructions and access scope. Retention, deletion, export, legal hold and backup handling are settled in the applicable agreement and tenant documentation; there is no universal retention period in the public draft. The signed data-processing agreement and tenant-specific supplier schedule identify approved providers and locations.

On this public site, optional browser preferences can be reviewed through . The service and desktop notices are separate from website cookie choices.

Requests and questions

Depending on applicable law and the controller or processor role, individuals may have rights of access, correction, deletion, portability, restriction or objection. For service data, start with your organization's administrator. For public-site questions or help routing a privacy request, email support@falconcortex.com. Please do not include passwords, tokens or raw employee data in an initial message.