ASTRA CORTEX —:—:—PT/EN
Discovery → Delivery
SEC. 01 / 04 000° 0%

◇ SECURITY & GOVERNANCE

Governance that acts,not just observes.

Guardrails that block, budgets that stop execution, gates that hold critical vulnerabilities. In ASTRA Cortex, governance policy isn't a report: it's part of the pipeline.

◇ Layers of protection

Protection at every layer of the cycle.

Guardrails

AI under policy

Configurable protections against secret leakage, personal data and improper content in AI interactions, applied before they become a problem.

SecretsPersonal dataImproper content
Cost

Budget with a hard cap

Monthly AI budget per project with a real-time meter and limits that stop execution. Predictable spend, no surprises.

Dependency chain

Inventory and scanning on every build

Dependency inventory generated on every build and continuous vulnerability scanning. Found something critical? The gate holds the delivery until it's resolved.

SBOM per buildContinuous scanBlocking gate
Audit

Complete trail

Every agent decision recorded with author, context and cost. Exportable whenever compliance asks.

Identity

Your organization, your access rules

Full isolation per organization and single sign-on with your company's identity provider, with automatic user provisioning.

SSO · SAML / OIDCIsolation per organization
Data

Your data, yours only

Nothing you put into the platform trains an AI model. Ever.

◇ Commitments

What we put our name to.

Security isn't a marketing page: it's architecture. Every commitment on the side is implemented in the product and can be verified in your own environment during early access.

Need a specific detail for your compliance? Talk to the team: we're glad to answer security questionnaires.

EncryptionTLS in transit · secrets encrypted at rest
IsolationPer organization
Model trainingNever with your data
PrivacyLGPD
AuditExportable per project

◇ Security questions

What your risk team will ask.

Code lives in the git repository of your choice and deploys happen on the infrastructure you point to. Product artifacts stay isolated per organization, with encryption in transit and secrets encrypted at rest.

With the policy in blocking mode, the guardrail stops the action before execution; in warning mode, it records and continues. In both cases the event goes to the audit trail and, if you configure it, the people responsible are notified immediately.

Every build generates a dependency inventory that is scanned for known vulnerabilities. Severity above the threshold you set blocks the quality gate: the delivery only proceeds once it's resolved.

Yes. Every decision, human or agent, is recorded with author, timestamp, context and originating evidence, and the history is exportable per project.

◇ Early access

Trust is demonstrated.

Verify every commitment in your own environment during early access.

Request early access