Security and data boundaries
On this page
Security review should address the proposed deployment and workflow. The Coryntas Trust Center distinguishes current website controls from agent controls configured for each customer deployment.
Start with the deployment boundary#
Identify which systems, data categories, users, environments, and operations the workflow needs. Document what is excluded. The review should cover both the information used to prepare an answer and any action taken in another system.
Website security practices do not establish the hosting or data handling of a customer's agent deployment. Request information for the specific architecture and workflow being considered.
Review access and action controls#
Coryntas describes permission-aware context, scoped tools, approval boundaries, execution evidence, and controlled change as parts of its agent operating model. Confirm how those controls apply to your roles, systems, and decisions.
Include unauthorized access and denied actions in evaluation. Review the evidence and escalation path when a workflow encounters a boundary it cannot cross. See Prepare access and permissions.
Confirm data handling#
Ask your implementation and security teams to confirm where relevant data is processed and stored, what is retained, who has access, and which providers are involved. Requirements for sensitive data, deletion, and retention should be documented for the deployment.
Do not transfer the website's public-form retention period to agent data. They are different contexts. Similarly, do not assume a certification, regional hosting option, or contractual commitment that has not been provided for review.
Request security information#
Visit the Trust Center for public material. Its resources describe how to request architecture, data handling, deployment controls, and security questionnaire information.
Include the proposed systems, data categories, and workflow so the response can address the relevant boundary. Share sensitive evidence only through the agreed process. Use the Privacy Statement for the practices it specifically describes.
Last updated on