Kliper
Sign in Book a demo
Kliper
SECURITY & TRUST

Trust isn’t a page. It’s the product.

Kliper holds the most sensitive thing a QSA touches — evidence of how money is protected. Isolation, encryption, and a complete audit trail aren’t features here; they’re the foundation.

Per-tenant isolation Per-tenant encryption No training on your data
§01ISOLATION

Your tenant is a wall, not a setting.

PER-TENANT

Logical isolation

Every firm’s ROCs, evidence, and prompts live in a logically isolated store. Retrieval can only cross within the boundary of your engagement.

ENCRYPTION

In transit & at rest

TLS 1.2+ everywhere; data is encrypted at rest with AES-256.

AUDIT TRAIL

Every action logged

Who did what, when — including every Cortex action. Exportable audit logs on Team and above for your own evidence.

§02CERTIFICATIONS

Attested, not asserted.

SOC 2 Type II
Audit underway — report on request when complete
IN PROGRESS
PCI DSS v4.0.1 aligned
We hold ourselves to our own standard
ALIGNED
GDPR & DPA ready
Data processing agreement on request
AVAILABLE
Penetration tested
Third-party tests, at least annually
ANNUAL
§03DATA & CORTEX

Your data trains nothing outside your tenant.

Cortex is retrieval, not training. It reads your past ROCs, evidence, and the framework text to draft — and nothing of yours is ever used to train shared models or improve another customer’s results.

  • No cross-customer learning — ever
  • Every draft cites the source it drew from
  • You can delete your tenant data on request
  • Sub-processors are listed and kept current
AI-use declaration · aligned to PCI SSC “Integrating AI in PCI Assessments”

Cortex helps your assessor draft narratives, summarize evidence, and answer PCI DSS questions — always under the assessor’s review. Cortex makes no compliance decision: your Qualified Security Assessor reviews and approves every finding. Cardholder data and sensitive information are redacted before any AI processing, and the AI runs on infrastructure that does not use your data for training. Every assessment carries this declaration in its engagement letter and client portal.

§04PRACTICES

How we operate.

ACCESS

Least-privilege access

Role-based access and mandatory MFA for all Kortlabs staff. Our private infrastructure is reached only through Zero Trust network access (Twingate); production access is logged and time-boxed. SSO/SCIM is on the roadmap for Team and above.

MONITORING

Vuln & threat management

Continuous dependency scanning, vulnerability remediation SLAs, and alerting on anomalous access.

RESPONSE

Incident & disclosure

A documented incident response plan and a responsible-disclosure channel at [email protected]. We notify affected tenants promptly.