Security by construction, not by policy PDF.
Falcon Cortex is being engineered around database-enforced tenant boundaries, tamper-evident evidence, governed identity, and independent approval for selected high-risk workflows. The current posture is an engineering and controlled-UAT posture—not a production certification.
The nine controls that carry the weight.
Status is stated per control. Implemented means present in the current engineering source and locally tested where evidence exists; it does not mean deployed, independently audited, or certified.
Tenant boundaries
RLS-based platform, tenant, and workspace controls are present across the governed schema and remain subject to exact-state coverage and adversarial isolation tests.
Privileged-action gates
Step-up and independent-approval primitives exist for selected sensitive operations. Coverage is validated operation by operation; it is not claimed for every destructive action.
Append-only audit evidence
Append-only audit paths and verification prototypes are implemented in source. Complete workflow coverage, independent anchoring, lifecycle commitments, and production operation remain release gates.
Enterprise identity
MFA, approved-domain, session, SSO, and SCIM surfaces require identity-provider configuration and end-to-end tenant validation before rollout.
Secrets and keys
Server-only secret handling, envelope-custody components, and one-time-reveal key patterns are implemented and require environment-specific operational verification.
Data isolation
Tenant and workspace identifiers, governed functions, and RLS policies form the isolation model. Production assurance depends on clean migration, runtime, and cross-tenant proof.
Conditional access
MFA, session, device, and network policy surfaces are being integrated. Enforcement claims are made only after the applicable tenant flow passes runtime tests.
Residency and data lifecycle
Residency, lifecycle, backup, and export requirements are agreed during discovery. No multi-region production availability or universal lifecycle commitment is claimed on this page.
Change assurance
Schema and application changes use reviewable migrations, local tests, secret checks, rollback planning, and independent audit. Production release approval is not yet claimed.
What we're aligned to — and honest about the roadmap.
SOC 2
Not certifiedEngineering and evidence practices are being mapped to relevant Trust Services Criteria. Falcon Cortex has no SOC 2 report at this time.
ISO/IEC 27001:2022
Not certifiedSecurity engineering is being organised against relevant ISO/IEC 27001 control themes. No certificate or completed independent conformity assessment is claimed.
Privacy and GDPR
Readiness in progressMinimisation, consent, access, retention, deletion, and sub-processor requirements are being built into the product. Controller/processor roles and lawful basis are customer- and jurisdiction-specific.
Healthcare workloads
Assessment requiredFalcon Cortex is not represented as HIPAA compliant and no BAA availability is claimed. Healthcare use requires legal, privacy, security, and contractual assessment.
Payment data
Out of current product scopeThe enterprise engagement has no public checkout. Payment-card processing and PCI scope are not represented as a live Falcon Cortex capability.
Other jurisdictions
Customer-specificApplicable employment, monitoring, privacy, residency, and labour requirements are assessed before capture activation. No universal legal-compliance claim is made.
Reference flow for the current engineering architecture.
Reference architecture only. Exact enforcement coverage, external anchoring, and operational verification must pass the release evidence gates for the deployed environment.
Read the current security engineering brief.
Written for security architects, privacy teams, and auditors. It separates implemented source controls, validation still in progress, planned deployment controls, and independent assurance not yet obtained.
- · Row-level security model with per-scope policy proofs
- · Tamper-evident evidence design and external-anchor release gate
- · Privileged-action approval patterns and current limitations
- · Key-management design and environment-specific validation
- · Sub-processor transparency and customer responsibility boundaries
Report a vulnerability
Send a report with clear reproduction steps to support@falconcortex.com. Do not include credentials, personal data, or exploit another tenant. Receipt targets and safe-harbour terms will be published only after the formal programme is approved.