Security & Confidentiality Policy
Effective Date: August 1, 2026
Corsantic ("Corsantic," "we," "our," or "us") is committed to protecting the confidentiality, integrity, and availability of customer information. This Security & Confidentiality Policy outlines the administrative, technical, and organizational safeguards we use to protect information entrusted to us.
1. Our Commitment
We understand that customers trust us with business information, documents, AI workloads, and other sensitive data.
Protecting that information is a core part of our services and operations.
2. Information Security Principles
Our security program is built around the following principles:
- Confidentiality
- Integrity
- Availability
- Least-privilege access
- Defense in depth
- Continuous improvement
- Risk management
3. Administrative Safeguards
We implement administrative safeguards that may include:
- Employee confidentiality obligations
- Security awareness training
- Access approval procedures
- Vendor risk assessments
- Incident response procedures
- Change management practices
- Internal security policies
- Periodic review of security controls
4. Technical Safeguards
Where appropriate, we implement technical controls such as:
- Encryption of data in transit using industry-standard protocols
- Encryption of data at rest where supported
- Multi-factor authentication for administrative access
- Role-based access controls
- Secure authentication mechanisms
- Network segmentation
- Firewalls and traffic filtering
- Endpoint protection
- System monitoring and logging
- Vulnerability management
- Backup and recovery procedures
The safeguards used may vary depending on the services provided and the deployment model.
5. Customer-Owned Infrastructure
For deployments on customer-owned hardware or infrastructure:
- Customers retain primary responsibility for the physical and operational security of their systems.
- Corsantic will only access customer-managed environments when authorized by the customer or as otherwise agreed.
- Customers are responsible for maintaining operating systems, network security, and physical access controls unless these services are included in a separate agreement.
6. Access Controls
Access to customer information is restricted to authorized personnel who require access to perform their responsibilities.
Access permissions are reviewed periodically and removed when no longer required.
7. Confidential Information
Corsantic treats customer information as confidential unless it is publicly available or disclosure is authorized by the customer or required by law.
Employees, contractors, and service providers with access to confidential information are expected to maintain appropriate confidentiality obligations.
8. Data Handling
Customer information is processed only as necessary to:
- Provide requested services
- Deliver customer support
- Maintain platform functionality
- Improve system reliability
- Meet legal obligations
- Protect the security of our services
We do not sell customer information.
9. Third-Party Service Providers
We may use trusted third-party providers for services such as:
- Cloud hosting
- Authentication
- Payment processing
- Analytics
- Customer support
- Infrastructure management
Where appropriate, these providers are contractually required to protect customer information.
10. AI Processing
Customer information submitted for AI processing is used only to provide the requested services unless otherwise agreed in writing.
Unless explicitly stated otherwise, Corsantic does not use customer-uploaded content to train publicly available AI models without customer permission.
11. Monitoring
To protect our services and customers, we may monitor:
- Service availability
- Authentication activity
- Security events
- Infrastructure health
- Performance metrics
- System logs
Monitoring is performed for operational, security, and compliance purposes.
12. Incident Response
If we become aware of a security incident affecting customer information, we will:
- Investigate the incident.
- Take reasonable steps to contain and mitigate its impact.
- Restore affected systems where appropriate.
- Notify affected customers when required by applicable law or contractual obligations.
13. Business Continuity
We maintain procedures intended to support the continued operation and recovery of our services following significant operational disruptions.
Recovery measures may include backups, redundancy, and disaster recovery planning, where appropriate.
14. Customer Responsibilities
Customers are responsible for:
- Maintaining strong passwords.
- Enabling multi-factor authentication where available.
- Protecting account credentials.
- Managing user permissions.
- Backing up important data.
- Securing customer-managed infrastructure.
- Promptly reporting suspected security incidents.
15. Compliance
Corsantic strives to operate in accordance with applicable privacy and security laws and regulations relevant to our business and the jurisdictions in which we operate.
Customers remain responsible for ensuring that their own use of the Services complies with applicable legal and regulatory requirements.
16. Changes to This Policy
We may update this Security & Confidentiality Policy from time to time to reflect changes in our services, technology, legal obligations, or security practices.
Updated versions become effective when published on our website.
17. Contact
Questions regarding this Security & Confidentiality Policy may be directed to:
Corsantic
Email: admin@corsantic.com
Website: https://corsantic.com
Last Updated: August 1, 2026