Cortex
PrivacyTermsData processing

Data processing · technical publication

Know where company data can go.

Cortex uses a bounded service chain to host the product, connect accounts, run approved model routes, and operate the service. Which services receive a company’s data depends on the deployed configuration and the connections that company chooses.

DPA statusCounsel-review template

The repository contains a working draft. It is not an executed agreement and no customer should be told otherwise.

Subprocessor statusTechnical candidate register

The list below reflects the documented architecture. Production activation and vendor terms still require founder verification.

Assurance statusNo certification claim

Cortex has a readiness control map and implementation evidence. It is not represented as SOC 2 certified.

Production statusNot yet evidenced here

This source tree does not contain a verified production origin or completed Phase 8 production smoke receipt.

Expected production chain

Core services in the documented deployment.

“Expected” is deliberate: this page does not turn an unverified dashboard configuration into a completed production claim.

ServicePurposeActivation boundary
VercelWeb application and server-route hostingExpected core production service
RailwayWorker and webhook-service hostingExpected core production service
SupabaseManaged PostgreSQL and private export-object storageExpected core production service
ClerkUser authentication and organization identityExpected core production service
InngestDurable job scheduling and executionExpected core production service
NangoConnected-account authorization, credential brokerage, and sync orchestrationWhen live integrations are enabled
LangfuseModel tracing, token and cost metrics, and redacted operational diagnosticsDocumented production observability profile
SentryError monitoring and performance diagnosticsDocumented production observability profile
PostHogPseudonymous product analytics and activation eventsDocumented production analytics profile
ResendTransactional account and member emailWhen production email is configured

Configuration-dependent

Used only when the named feature or route is enabled.

Connection-time disclosures identify approved model processors and selected provider scope before ingestion begins.

ServicePurposeActivation boundary
OpenAIModel inference and embeddingsOnly when a tenant-approved route uses OpenAI
AnthropicModel inferenceOnly when a tenant-approved route uses Anthropic
Google CloudModel inferenceOnly when a tenant-approved route uses Google
Vercel AI GatewayRouting to a configured model providerOnly when the AI Gateway route is configured
StripeSubscription billing and test-mode meteringOnly when Cortex billing is configured
WorkOSScale-plan SAML or OIDC single sign-onOnly when a company enables enterprise SSO
TavilyCited public-web search for Competitor WatchOnly when web search is configured

Customer-directed services

Your connected account remains your choice.

Google Workspace, Drive, Calendar, Slack, HubSpot, QuickBooks, and a company’s Stripe source are services the company directs Cortex to connect. Their independent terms govern the company’s relationship with them. Nango remains the Cortex-appointed connection and proxy layer when that path is enabled.

Recorded fixtures, local Docker, Vitest, Playwright, evaluation tooling, and developer workstations are not approved destinations for production customer data.

Before a partner signs

The legal document must match the production system.

Cortex still needs a confirmed legal entity, privacy contact, effective date, change-notice mechanism, transfer terms, backup and deletion periods, and counsel-approved audit terms before its DPA can be executed.

Read the implemented security storyRead the privacy notice

Cortex