Skip to main content
Security & Compliance

Security by construction, not by policy PDF.

Falcon Cortex is being engineered around database-enforced tenant boundaries, tamper-evident evidence, governed identity, and independent approval for selected high-risk workflows. The current posture is an engineering and controlled-UAT posture—not a production certification.

SOC 2
mapping in progress
ISO 27001
mapping in progress
Privacy
governed workflows
Tenant isolation
RLS-based design
Governed AI
human controlled
Auditability
evidence in UAT
Control catalogue

The nine controls that carry the weight.

Status is stated per control. Implemented means present in the current engineering source and locally tested where evidence exists; it does not mean deployed, independently audited, or certified.

Tenant boundaries

Implemented locally

RLS-based platform, tenant, and workspace controls are present across the governed schema and remain subject to exact-state coverage and adversarial isolation tests.

Privileged-action gates

Implemented in selected workflows

Step-up and independent-approval primitives exist for selected sensitive operations. Coverage is validated operation by operation; it is not claimed for every destructive action.

Append-only audit evidence

Engineering build

Append-only audit paths and verification prototypes are implemented in source. Complete workflow coverage, independent anchoring, lifecycle commitments, and production operation remain release gates.

Enterprise identity

Tenant-configured UAT

MFA, approved-domain, session, SSO, and SCIM surfaces require identity-provider configuration and end-to-end tenant validation before rollout.

Secrets and keys

Engineering build

Server-only secret handling, envelope-custody components, and one-time-reveal key patterns are implemented and require environment-specific operational verification.

Data isolation

Implemented locally

Tenant and workspace identifiers, governed functions, and RLS policies form the isolation model. Production assurance depends on clean migration, runtime, and cross-tenant proof.

Conditional access

Controlled-UAT preparation

MFA, session, device, and network policy surfaces are being integrated. Enforcement claims are made only after the applicable tenant flow passes runtime tests.

Residency and data lifecycle

Customer-specific design

Residency, lifecycle, backup, and export requirements are agreed during discovery. No multi-region production availability or universal lifecycle commitment is claimed on this page.

Change assurance

Local gates active

Schema and application changes use reviewable migrations, local tests, secret checks, rollback planning, and independent audit. Production release approval is not yet claimed.

Frameworks

What we're aligned to — and honest about the roadmap.

SOC 2

Not certified

Engineering and evidence practices are being mapped to relevant Trust Services Criteria. Falcon Cortex has no SOC 2 report at this time.

ISO/IEC 27001:2022

Not certified

Security engineering is being organised against relevant ISO/IEC 27001 control themes. No certificate or completed independent conformity assessment is claimed.

Privacy and GDPR

Readiness in progress

Minimisation, consent, access, retention, deletion, and sub-processor requirements are being built into the product. Controller/processor roles and lawful basis are customer- and jurisdiction-specific.

Healthcare workloads

Assessment required

Falcon Cortex is not represented as HIPAA compliant and no BAA availability is claimed. Healthcare use requires legal, privacy, security, and contractual assessment.

Payment data

Out of current product scope

The enterprise engagement has no public checkout. Payment-card processing and PCI scope are not represented as a live Falcon Cortex capability.

Other jurisdictions

Customer-specific

Applicable employment, monitoring, privacy, residency, and labour requirements are assessed before capture activation. No universal legal-compliance claim is made.

Architecture

Reference flow for the current engineering architecture.

Browser · DesktopSession + JWTEdge · TanStack StartBearer verify · ZodPostgres + RLSprivate.* helpersaudit evidenceintegrity evidence designIdentity policytenant-configured UATVault PII (AES)Column-level cryptoExternal anchorrelease gateSelected sensitive workflows · independent approvalrequest → validate → approve → execute → evidence

Reference architecture only. Exact enforcement coverage, external anchoring, and operational verification must pass the release evidence gates for the deployed environment.

Deep dive

Read the current security engineering brief.

Written for security architects, privacy teams, and auditors. It separates implemented source controls, validation still in progress, planned deployment controls, and independent assurance not yet obtained.

  • · Row-level security model with per-scope policy proofs
  • · Tamper-evident evidence design and external-anchor release gate
  • · Privileged-action approval patterns and current limitations
  • · Key-management design and environment-specific validation
  • · Sub-processor transparency and customer responsibility boundaries
Public technical brief

No gated download. No certification theatre.

Read the maintained HTML brief, print it, or save it as PDF. Statements are deliberately scoped to the current engineering state.

Report a vulnerability

Send a report with clear reproduction steps to support@falconcortex.com. Do not include credentials, personal data, or exploit another tenant. Receipt targets and safe-harbour terms will be published only after the formal programme is approved.