The repository contains a working draft. It is not an executed agreement and no customer should be told otherwise.
Data processing · technical publication
Know where company data can go.
Cortex uses a bounded service chain to host the product, connect accounts, run approved model routes, and operate the service. Which services receive a company’s data depends on the deployed configuration and the connections that company chooses.
The list below reflects the documented architecture. Production activation and vendor terms still require founder verification.
Cortex has a readiness control map and implementation evidence. It is not represented as SOC 2 certified.
This source tree does not contain a verified production origin or completed Phase 8 production smoke receipt.
Expected production chain
Core services in the documented deployment.
“Expected” is deliberate: this page does not turn an unverified dashboard configuration into a completed production claim.
| Service | Purpose | Activation boundary |
|---|---|---|
| Vercel | Web application and server-route hosting | Expected core production service |
| Railway | Worker and webhook-service hosting | Expected core production service |
| Supabase | Managed PostgreSQL and private export-object storage | Expected core production service |
| Clerk | User authentication and organization identity | Expected core production service |
| Inngest | Durable job scheduling and execution | Expected core production service |
| Nango | Connected-account authorization, credential brokerage, and sync orchestration | When live integrations are enabled |
| Langfuse | Model tracing, token and cost metrics, and redacted operational diagnostics | Documented production observability profile |
| Sentry | Error monitoring and performance diagnostics | Documented production observability profile |
| PostHog | Pseudonymous product analytics and activation events | Documented production analytics profile |
| Resend | Transactional account and member email | When production email is configured |
Configuration-dependent
Used only when the named feature or route is enabled.
Connection-time disclosures identify approved model processors and selected provider scope before ingestion begins.
| Service | Purpose | Activation boundary |
|---|---|---|
| OpenAI | Model inference and embeddings | Only when a tenant-approved route uses OpenAI |
| Anthropic | Model inference | Only when a tenant-approved route uses Anthropic |
| Google Cloud | Model inference | Only when a tenant-approved route uses Google |
| Vercel AI Gateway | Routing to a configured model provider | Only when the AI Gateway route is configured |
| Stripe | Subscription billing and test-mode metering | Only when Cortex billing is configured |
| WorkOS | Scale-plan SAML or OIDC single sign-on | Only when a company enables enterprise SSO |
| Tavily | Cited public-web search for Competitor Watch | Only when web search is configured |
Customer-directed services
Your connected account remains your choice.
Google Workspace, Drive, Calendar, Slack, HubSpot, QuickBooks, and a company’s Stripe source are services the company directs Cortex to connect. Their independent terms govern the company’s relationship with them. Nango remains the Cortex-appointed connection and proxy layer when that path is enabled.
Recorded fixtures, local Docker, Vitest, Playwright, evaluation tooling, and developer workstations are not approved destinations for production customer data.