coryntasTrust Center

Security, privacy, and assurance

Trust is built into the work.

Coryntas designs identity, permissions, action boundaries, approvals, evidence, and human judgment into enterprise agent workflows.

Trust Center

Controls

17 published controls, with status language that distinguishes the current website from customer-specific deployment design.

Content reviewed August 3, 2026

Website infrastructure

Controls observable in the current coryntas.com website and delivery worker.

3 controls

Encrypted transport enforced

The production site uses HTTPS and sends a long-lived Strict-Transport-Security header on secure responses.

Implemented

Browser security headers applied

Responses apply content type, framing, referrer, permissions, and cross-origin protections.

Implemented

Content Security Policy defined

The website restricts scripts, frames, connections, images, forms, and object sources to the services it uses.

Implemented

Form and application security

Safeguards applied to public form submissions and the supporting API.

4 controls

Same-origin submission checks

API requests are rejected when their origin does not match the configured Coryntas site origin.

Implemented

Automated abuse detection

Cloudflare Turnstile verifies public form submissions outside local preview environments.

Implemented

Request validation and size limits

The API normalizes input, validates required fields and enums, and rejects oversized JSON payloads.

Implemented

Network-derived rate limiting

Public submissions are rate limited using salted, time-bounded hashes rather than storing raw network addresses in request records.

Implemented

Data and privacy

Current website practices documented in the Coryntas Privacy Statement.

3 controls

Optional analytics requires consent

Google Analytics 4 is not loaded until a visitor accepts optional analytics.

Implemented

Public request retention is bounded

Demo and security-information requests that do not become customer records are retained for up to 12 months.

Implemented

Short-lived rate-limit records

Scheduled cleanup removes expired rate-limit records after their limited protection window.

Implemented

Agent governance

Control patterns Coryntas configures around each customer workflow.

4 controls

Permission-aware context

Source access and workflow purpose are preserved when retrieving knowledge and live records.

Configured per deployment

Scoped actions

Tools can be limited by identity, role, system, operation, field, state, threshold, and permitted side effect.

Configured per deployment

Approval policy

Sensitive, ambiguous, or high-impact decisions can be routed to the accountable human authority.

Configured per deployment

Execution evidence

Sources, decisions, tool calls, approvals, exceptions, and resulting system state can be recorded for review.

Configured per deployment

Deployment assurance

Requirements confirmed against the systems, data, operating model, and customer environment in scope.

3 controls

Hosting boundary review

Hosting, network, storage, and model-provider boundaries are documented for the proposed deployment.

Configured per deployment

Retention requirements review

Retention and deletion expectations are agreed for the data and records used by the workflow.

Configured per deployment

Change and evaluation path

Context, tools, policy, prompts, and workflow changes are evaluated before controlled release.

Configured per deployment