← C0RTEX
Trust & Security

Security at C0RTEX

C0RTEX is an AI customer-support service operated by Perfect Paradox Ltd. This page explains, in plain terms, how we protect your data and your customers' data. It describes our current technical and organisational measures — not marketing.

01Per-client isolation

C0RTEX is single-tenant by design. Each customer runs in their own isolated Docker container, with their own encrypted data volume, their own subdomain and their own resource quota. One customer's data is never co-mingled with another's in a shared database.

02Encryption

At rest

Customer data is stored on an AES-256-GCM encrypted filesystem (gocryptfs). Backups snapshot the ciphertext only — plaintext never leaves the running service.

In transit

All traffic is served over HTTPS/TLS with automatically renewed certificates (Let's Encrypt). HSTS is enforced.

03Access & authentication

04Your data & the AI

05Sub-processors

We use a small, named set of providers. Each is bound by its own data-processing terms:

ProviderPurposeRegion
AnthropicLanguage model (Claude) that drafts answersUS
HostingerServer hosting (VPS)EU
PaddlePayments & invoicing (Merchant of Record, handles VAT)UK/EU
ResendTransactional email (verification, notifications)US/EU
Let's EncryptTLS certificates

06Backups & recovery

Encrypted backups run on a daily schedule: 14 days retained on the server and 90 days off-site, with integrity verified (SHA-256) and restoration tested. Because we snapshot the ciphertext, backups are useless without the separately held encryption key.

07Compliance & legal

08Certifications

C0RTEX follows practices aligned with recognised security frameworks (SOC 2 and ISO/IEC 27001 control areas: access control, encryption, change management, incident response, vendor management). We are not yet independently certified — we'll pursue formal SOC 2 / ISO 27001 audits as we scale and where enterprise customers require them. For due-diligence or a security questionnaire, contact us and we'll share our current documentation.

Responsible disclosure. Found a security issue? Email security@perfectparadox.co.uk (or info@perfectparadox.co.uk). We'll acknowledge and work with you in good faith; please don't access data that isn't yours.