Implemented controls, stated plainly.
What is delivered today, what is on the roadmap, and how to reach us for vendor assessment.
This page lists what is implemented today and what is on the roadmap. Roadmap items are labelled as such and are not represented as delivered controls anywhere on this site.
Control status
| Control | What it means | Status |
|---|---|---|
| Deterministic scoring | Normalised signal scores are computed by fixed rules; AI assists identification only. | Implemented |
| Append-only evidence registry | Observations are never overwritten; corrections supersede and both are retained. | Implemented |
| Provenance chain | Every recommendation links back through judgment → belief → observation → testimony. | Implemented |
| Human-governed approvals | Material approvals and governance transitions are attributable human actions. | Implemented |
| Role-scoped access | Users act only within their authorised role and tenant context. | Implemented |
| Unified audit history | Permissioned actions, denials, state changes, approvals and exports flow into a tamper-evident log. | Roadmap |
| Third-party certification (SOC 2 / ISO 27001) | No certification is claimed. Status will be published here when an audit is complete. | Roadmap |
| Encryption in transit / at rest | TLS 1.2+ in transit. At-rest encryption via cloud provider managed keys. | Implemented |
| Tenant isolation | Logical isolation per tenant with row-level access controls. | Implemented |
| Data residency options | Region selection for enterprise tenants. | Roadmap |
Hosting and architecture
The marketing site is a static site on Vercel. The CORTEX platform is hosted on a major cloud provider in the UK/EU; architecture summary and network diagram are available under NDA on request.
Sub-processors
- Vercel — website hosting
- Form provider — discovery request handling (named in the Privacy Notice once configured)
- Cloud provider — platform hosting
Data lifecycle
Discovery request data is retained for up to 24 months after last contact. Platform tenant data lifecycle is governed by the customer agreement and DPA.
Security contact
security@purpleailabs.io — for vulnerability reports and incident contact. We acknowledge reports within two working days.
Vendor assessment
Security questionnaires (CAIQ, SIG-Lite, or your own) and a Data Processing Agreement are available on request via hello@purpleailabs.io.
Last reviewed 15 August 2026. Items marked Roadmap are planned and not yet delivered.