MindshineMindshineCortex documentation v1.0.790

Security and operations

Cortex runs on one AWS EKS cluster in two environments, with the controls a financial-software evaluation expects: tenant isolation by project, fail-closed access control shared by every service, attributed writes, per-project secrets, hardened pods, in-cluster image builds, health watchdogs with alerting, and a SOC 2 readiness programme documented on the trust center. This page summarises the operational and security posture; the technical detail behind each control is in the repository and on trust.tiva-ai.com.

Tenancy and isolation

Identity and access

Attribution and audit

Secrets

Infrastructure and delivery of the platform

Observability and health

Compliance posture

The trust center publishes the security and compliance package: information security, access control, data protection, vulnerability management, secure development, incident response, business continuity, change management, vendor risk, retention, cloud infrastructure, penetration testing, a SOC 2 control matrix and the readiness findings report. It is management-prepared documentation on the road to a SOC 2 Type II report; it is not itself an audit report.

What is not yet in place

For completeness of an evaluation: refresh tokens are not implemented on the MCP OAuth server (bearers do not expire and are revoked by deletion); the Rust single-binary runtime is not the production runtime; an unregistered agent (one the registry has not yet synchronised) is visible to project members by a documented default flag.