Trust
Trust centre
Last reviewed: 2026-09-23
Cortex is the governed AI desktop: it answers from your company's files and meetings, runs on the laptop by default so sensitive work never leaves it, and puts every AI agent your engineers use — Claude Code, Codex — under one policy and one audit trail.
This page lists what we can stand behind today, what is still being built, and what we do not claim. If something here is out of date, tell us at security@swfte.com.
True today
- Customer data is stored in AWS eu-west-1 (Ireland).
- Encryption at rest: the RDS databases are encrypted, most DynamoDB tables use a KMS key (the remainder are being moved onto it), and S3 uses SSE-S3.
- API traffic uses TLS 1.2 or later (TLS 1.3 preferred).
- On-device mode: prompts are processed by a local model on your Mac and are not sent to Swfte or model providers.
- Screen capture, microphone listening and wake word are all off by default.
- Product telemetry is off by default.
- Computer-use actions are recorded in a local audit log.
- Local models downloaded from Hugging Face are pinned to a fixed revision and checksum-verified.
- Sign-in via Google, Microsoft or GitHub through WorkOS.
Policy statement pending confirmation: <founder to confirm this is contractually backed before publishing: "Swfte does not use your prompts or files to train models.">
In progress
| Item | Status | Target |
|---|---|---|
| SOC 2 Type I audit | In preparation | <target date — founder to fill> |
| External penetration test | Not yet performed | <target date — founder to fill> |
| Enterprise SAML SSO and SCIM provisioning | In development | <target date — founder to fill> |
| MFA enforcement | In development | <target date — founder to fill> |
| Zero-data-retention agreements with model providers | In progress | <target date — founder to fill> |
| Data Processing Agreement (DPA) | Draft template, pending legal review | <target date — founder to fill> |
We will provide a security questionnaire, an architecture overview and the DPA on request.
What we do not claim
None of the following is true today. If you read one of them elsewhere on our site, it is an error — please report it.
- SOC 2 (any type) — no report exists yet.
- ISO 27001 certification.
- HIPAA compliance, or signing a Business Associate Agreement (BAA).
- Customer-managed encryption keys.
- End-to-end encryption.
- A 99.99% uptime SLA.
- SAML SSO, SCIM or end-user MFA today.
- An external penetration test.
- Immutable audit logs or a 24/7 security operations centre.
- Data residency options beyond AWS eu-west-1.
Trust documents
- Security and responsible disclosure
- Sub-processors (draft)
- Data Processing Agreement (draft template)
- Model cards by intelligence level
Contact
Security questions and vulnerability reports: security@swfte.com. See responsible disclosure for what to include.