Trust

Trust Center

Last updated · August 24, 2026

Security, privacy, and operational accountability are product surfaces at Coaray—not claims reserved for a sales process. This page records how we approach customer data, which controls are operating, and where assurance work is still in progress.

We do not present an audit, certification, or regulated-workload capability as complete until it can be evidenced. Firms evaluating Coaray can ask for the control details that matter to their deployment and receive a clear answer about current scope.

Assurance status

Current posture, without the theatre.

Operating safeguards are separated from roadmap work and independent assurance.

Product controls

Operating

Independent assurance

Not yet asserted

Privacy programme

In development

Regulated workloads

Scope before use

Controls

The operating system behind trust.

Six control families shape how work, data, people, and agents are allowed to move.

01

Infrastructure and network

Production boundaries are configured to limit public exposure, separate privileged paths, and keep operational access intentional.

  • Encrypted transport
  • Environment separation
  • Restricted administrative paths
02

Data protection

Coaray treats client, matter, credential, and operational data as distinct classes with different handling requirements.

  • Authenticated credential encryption
  • Scoped data access
  • Deletion and export workflows
03

Identity and access

Authority is tenant-bound and action-specific. Sensitive operations enter through authenticated seams instead of shared service access.

  • Tenant-aware authorization
  • Least-privilege connections
  • Explicit approval boundaries
04

Agent guardrails

Agents receive the minimum context and capability needed for a task, with human review where judgment or external effects require it.

  • Task-scoped context
  • Approval before material effects
  • Visible action history
05

Monitoring and response

Operational changes and important actions are designed to produce reviewable records so unusual behaviour can be investigated.

  • Structured activity records
  • Failure-state visibility
  • Incident response ownership
06

Continuity and recovery

Recovery planning starts with clear ownership, recoverable data paths, and the ability to stop or isolate work safely.

  • Controlled pause states
  • Recoverable operational records
  • Documented escalation paths
Data handling

Customer data should have a visible path.

Collection, use, retention, and disclosure are treated as separate decisions.

Collection
Only the information needed to provide an authorized workflow.
Use
For the requested service, security, support, and legal obligations.
Retention
Based on account configuration, contractual instruction, and applicable law.
Disclosure
To authorized users, instructed connections, and contracted service providers.
Service providers

A register tied to the deployment.

Coaray confirms the applicable provider list during security review because enabled models, communication channels, and connected tools differ by firm.

CategoryPurposeScope
Data platformAuthentication, database, and authorized file storageDeployment-specific
Edge and networkTraffic delivery, protection, and request controlsDeployment-specific
Model providersAuthorized agent and language-model processingWorkflow-specific
CommunicationsEmail, messaging, and voice delivery when enabledConnection-specific
Resources

Review the details or ask directly.

Security contact

Bring us the question your firm needs answered.

Start a security review