What we hold, and what we will not do

demowho and where

Not a feature. Sign-in decides both of these; until then, this does.

Demo map
Setup

What we hold, and what we will not do

115 record sets · 1,936 records · 1.0 MB — yours to take out whenever you want, paying or not

What we hold

12

The same list an export contains and a deletion removes. Provenance, coverage honesty, refusals, deletion rights and this page work identically whether the company is paying or not.

  • People, roles and reporting linesthe org graph you built at joining
  • Goals, key results and key actionsthe plan and the cascade
  • Deals, enquiries, proposals, sequencesCorto CRM
  • Orders, dispatches, handoffs, purchase orders, receiptsOperations
  • Invoices, payables, promises to pay, the outboxread from the books; the books themselves are never touched
  • Tickets, assets, known answersthe service desk
  • Leave, letters, documents and who signed themHR
  • Every file anybody attachedthe files provider
  • Every agent proposal and who decided itthe approval record
  • Check-ins, one-to-ones, retrosTrack — in the person's own words
  • X-Ray and survey answersaggregate only; the individual answers are never stored against a name, so they cannot be exported against one eithernever held per person
  • The outside-in reportbuilt from public recordstays yours as a file after deletion

What we will not do

  • Show anybody a person's survey or check-in feelings — they are counted, never named, and never reach an appraisal.
  • Write to your books. Tally, Busy, Marg, Zoho Books and Xero stay yours; Corto reads them and hands your accountant a file.
  • Send anything outside the building without a named person's approval.
  • Log keystrokes, capture screens or track idle time — in any market.
  • Show a number without the record behind it, or estimate one it cannot compute.
  • Make any of this depend on the plan you are on.

Other companies that handle your data

18
  • App connectionsComposio for the long tail; owned adapters where strategic (the Tally read-only agent, bank-alert mail rules)
  • DatabasePostgres in Docker, locally — no account, no bill, no lock-in
  • ClaudeAnthropic
  • File storageCloudflare R2 / AWS S3
  • EmailResend / AWS SES / Postmark
  • Calendarcal.diy, self-hosted as a sidecar (MIT; Google, Microsoft 365, Zoho and CalDAV behind one API). Decided 2026-09-02. Replaceable by direct Google + Graph calls behind the same interface if the sidecar proves heavy.
  • The booksOn-prem Tally agent (own build) · Zoho Books for non-Tally tenants
  • Company recordsProbe42 / Tofler / Karza
  • GST filingsClearTax / Masters India / Sandbox
  • PresenceGoogle Places + a SERP provider
  • Company filesGoogle Drive + Sheets (Microsoft Graph for MS tenants)
  • Shared mailboxesGmail API, shared-mailbox scope
  • Bank signalAlert-mail parsers now · Setu AA / Finvu later
  • Speech to textA transcription API with word-level confidence and Indian-English models — not chosen yet. Word confidence is a hard requirement, not a nice-to-have; a provider that returns only a transcript cannot be used.
  • PushWeb Push (VAPID) now; Firebase Cloud Messaging for the app later
  • Public schemesmyScheme / state DIC portals / a Haqdarshak-class aggregator — per market
  • Market dataAn index and filings data provider — per market; ACMA/RBI/MCA sources in India
  • PaymentsRazorpay

The security review

  • Data Processing Agreement — signed25 Aug
  • Sub-processor list — disclosed, including where the model runs25 Aug
  • Data-residency confirmation25 Aug
  • Penetration-test summaryowed — does not block

The full record →