Security and compliance
Your trial data stays isolated, and stays yours.
Your own private instance, in your own region. Access is by role, and nothing you put in is used to train a model.
EU, US and UK data residency
Certifications held

The full security posture is documented at trust.cori-clinical.com. Certificates and the current subprocessor list are available under NDA. Ask on the call, or write to security@cori-clinical.com.
How it is built
The controls, group by group.
How your data is stored, who can reach it, and what the audit trail says.
Protection
Encryption at rest and in transit
AES-256 at rest, TLS 1.2 and 1.3 in transit, with keys rotated on a fixed schedule.
Continuous monitoring
Threats, vulnerabilities and anomalies are monitored continuously rather than periodically.
Access
Strict access controls
Role-based permissions and multi-factor authentication. Access that was refused is logged too, not just access that was granted.
Regional processing and hosting
Processed and hosted in your region. The region is set when your account is created, and support cannot change it.
Governance
Data ownership and confidentiality
Never used to train models, never shared without consent, reachable on a need-to-know basis.
Governance you can read off the screen
Access, controls and activity across every document and user, without assembling it by hand.
Good to know
The questions procurement asks first.
Is Cori certified?
Cori Clinical holds ISO/IEC 27001 certification and complies with the GDPR and the EU AI Act. The scope covers the design, development and operation of the platform, including customer trial data hosted in the EU, US and UK regions. The full posture, with certificates, lives at trust.cori-clinical.com.
Where is our trial data hosted?
Each customer runs in an isolated deployment, hosted in the EU, the US or the UK.
Is our data used to train models?
No. Customer content is never used to train models, and no model provider retains it. A zero data retention policy applies to every model call the platform makes.
What does the audit trail cover?
Every action is logged, and the log is enforced by the database rather than by the application, so an altered entry shows. Deleting a user does not erase what they did, and access that was refused is logged alongside access that was granted.
How do we report a security issue?
Write to security@cori-clinical.com. Reports are triaged on receipt and acknowledged before any public disclosure is coordinated.

The full detail, under NDA.
Book thirty minutes with us, or write to security@cori-clinical.com and we will take it from there.
