Product controls
Operating
Last updated · August 24, 2026
Security, privacy, and operational accountability are product surfaces at Coaray—not claims reserved for a sales process. This page records how we approach customer data, which controls are operating, and where assurance work is still in progress.
We do not present an audit, certification, or regulated-workload capability as complete until it can be evidenced. Firms evaluating Coaray can ask for the control details that matter to their deployment and receive a clear answer about current scope.
Operating safeguards are separated from roadmap work and independent assurance.
Operating
Not yet asserted
In development
Scope before use
Six control families shape how work, data, people, and agents are allowed to move.
Production boundaries are configured to limit public exposure, separate privileged paths, and keep operational access intentional.
Coaray treats client, matter, credential, and operational data as distinct classes with different handling requirements.
Authority is tenant-bound and action-specific. Sensitive operations enter through authenticated seams instead of shared service access.
Agents receive the minimum context and capability needed for a task, with human review where judgment or external effects require it.
Operational changes and important actions are designed to produce reviewable records so unusual behaviour can be investigated.
Recovery planning starts with clear ownership, recoverable data paths, and the ability to stop or isolate work safely.
Collection, use, retention, and disclosure are treated as separate decisions.
Coaray confirms the applicable provider list during security review because enabled models, communication channels, and connected tools differ by firm.