Safety & Policies

Data Privacy & Security Commitments

Cortiqa is engineered with security-first architecture. Your proprietary data, inputs, outputs, and embeddings are strictly protected and never used to train public foundation models.


Core Privacy Commitments

  • No Training on API Data: Cortiqa does not use customer inputs, prompts, completions, or embeddings sent to api.cortiqa.co to train or fine-tune public base models.
  • Customer Ownership: You retain all intellectual property rights to the prompts you submit and the completions generated by our models.
  • Zero Data Selling: We never sell customer information, usage metadata, or conversation histories to third parties.

Data Handling & Encryption

  • In Transit: All API communication is encrypted using TLS 1.3 with modern cipher suites.
  • At Rest: Stored customer credentials, logs, and billing data are encrypted using FIPS 140-2 validated AES-256 encryption.
  • Isolation: Multi-tenant isolation ensures memory spaces and ephemeral LPU buffers are wiped immediately between inference sessions.

Data Retention Schedules

By default, request metadata and prompts are retained for 30 days strictly for abuse detection and developer debugging, after which they are permanently deleted.

Zero Data Retention (ZDR)
Enterprise customers with strict compliance mandates (healthcare, banking, defense) can request Zero Data Retention, where prompt texts are never written to disk and exist only in ephemeral volatile memory.

Compliance & Enterprise DPA

Cortiqa complies with global privacy regulations including GDPR, CCPA/CPRA, and ISO/IEC 27001 standards.

To execute a formal Data Processing Addendum (DPA) or Business Associate Agreement (BAA), email our legal and security officers at team@cortiqa.co.

Was this page helpful?