Security review

demowho and where

Not a feature. Sign-in decides both of these; until then, this does.

Demo map
Setup

Security review

What their IT team needs before anything is connected

Cleared to connect

reviewer · Rohit Mehta

In India this is often the founder waving it through; here Rohit signed the DPA and asked for the ISO 27001 timeline. The pen-test summary is owed to him — it does not block connecting, and he was told so.

Everything built from public records and the founder's own words carries on while this review runs. The only thing that waits is the financial data, and the report says so plainly. This step runs on the reviewer's timetable, not ours, so Corto never marks it late.

What the reviewer asks for

  • Data Processing Agreement — signed25 Aug
  • Sub-processor list — disclosed, including where the model runs25 Aug
  • Penetration-test summaryowed — does not block
  • Data-residency confirmation — from the residency step25 Aug
  • The security certificate buyers in this country actually ask for: ISO 27001in_progress

    In India the order is ISO 27001 → SOC 2 Type II. Certifications are product work, not sales admin — months each, and they gate deals once Corto is a system of record.

Where the data is stored, and where the AI runs

Both were decided as soon as we knew which country the business is in, before anything was saved at all.

Storage region
IN
Inference region
IN
Law
DPDP

The conversation brain runs on this machine (Ollama) until the Anthropic key arrives; the region is then the vendor's, disclosed on the trust page.

Other companies that would handle their data

This list is generated from the software itself, so it can never quietly fall out of date.

  • App connections

    Composio for the long tail; owned adapters where strategic (the Tally read-only agent, bank-alert mail rules)

  • Database

    Postgres in Docker, locally — no account, no bill, no lock-in

  • Claude

    Anthropic

  • File storage

    Cloudflare R2 / AWS S3

  • Email

    Any SMTP relay (Zimbra / AWS SES / Postmark all speak it)

  • Calendar

    cal.diy, self-hosted as a sidecar (MIT; Google, Microsoft 365, Zoho and CalDAV behind one API). Decided 2026-09-02. Replaceable by direct Google + Graph calls behind the same interface if the sidecar proves heavy.

  • The books

    On-prem Tally agent (own build) · Zoho Books for non-Tally tenants

  • Company records

    Probe42 / Tofler / Karza

  • GST filings

    GST Hero (gsthero.com), a GSP — lib/services/gst.ts

  • Presence

    Google Places + a SERP provider

  • Company files

    Google Drive + Sheets (Microsoft Graph for MS tenants)

  • Shared mailboxes

    Gmail API, shared-mailbox scope

  • Bank signal

    Alert-mail parsers now · Setu AA / Finvu later

  • Speech to text

    A transcription API with word-level confidence and Indian-English models — not chosen yet. Word confidence is a hard requirement, not a nice-to-have; a provider that returns only a transcript cannot be used.

  • Push

    Web Push (VAPID) now; Firebase Cloud Messaging for the app later

  • Public schemes

    myScheme / state DIC portals / a Haqdarshak-class aggregator — per market

  • Market data

    An index and filings data provider — per market; ACMA/RBI/MCA sources in India

  • Payments

    Razorpay

  • Organization wallet

    HiSociety (Lockated, internal — not a customer-facing vendor)

Corto asks for read-only access, and each permission is named on screen. It never writes into a company's own system without being explicitly given permission to.

What Corto is, in one sentence

What it replaces, and what it only reads

We replace your CRM, task lists, HR record and KPI tracking. We read your books, your shared mailboxes and your files — and never write to them.