Encrypted transport enforced
The production site uses HTTPS and sends a long-lived Strict-Transport-Security header on secure responses.
Security, privacy, and assurance
Coryntas designs identity, permissions, action boundaries, approvals, evidence, and human judgment into enterprise agent workflows.
Trust Center
17 published controls, with status language that distinguishes the current website from customer-specific deployment design.
Content reviewed August 3, 2026Controls observable in the current coryntas.com website and delivery worker.
The production site uses HTTPS and sends a long-lived Strict-Transport-Security header on secure responses.
Responses apply content type, framing, referrer, permissions, and cross-origin protections.
The website restricts scripts, frames, connections, images, forms, and object sources to the services it uses.
Safeguards applied to public form submissions and the supporting API.
API requests are rejected when their origin does not match the configured Coryntas site origin.
Cloudflare Turnstile verifies public form submissions outside local preview environments.
The API normalizes input, validates required fields and enums, and rejects oversized JSON payloads.
Public submissions are rate limited using salted, time-bounded hashes rather than storing raw network addresses in request records.
Current website practices documented in the Coryntas Privacy Statement.
Google Analytics 4 is not loaded until a visitor accepts optional analytics.
Demo and security-information requests that do not become customer records are retained for up to 12 months.
Scheduled cleanup removes expired rate-limit records after their limited protection window.
Control patterns Coryntas configures around each customer workflow.
Source access and workflow purpose are preserved when retrieving knowledge and live records.
Tools can be limited by identity, role, system, operation, field, state, threshold, and permitted side effect.
Sensitive, ambiguous, or high-impact decisions can be routed to the accountable human authority.
Sources, decisions, tool calls, approvals, exceptions, and resulting system state can be recorded for review.
Requirements confirmed against the systems, data, operating model, and customer environment in scope.
Hosting, network, storage, and model-provider boundaries are documented for the proposed deployment.
Retention and deletion expectations are agreed for the data and records used by the workflow.
Context, tools, policy, prompts, and workflow changes are evaluated before controlled release.