Trust
SOC Compatibility
How to evaluate Corgent against common SOC 2 style controls and security questionnaires.
SOC compatibility
Many teams need to evaluate vendors against SOC 2 style controls. This page explains how to map Corgent’s security approach to common questionnaire categories.
This page does not claim a specific certification. It’s meant to help you collect the right evidence and ask the right questions.
Typical control areas
Access control
- Role-based access to product features
- Authenticated APIs for uploads and user actions
- API key auth for public v1 invoke usage
Change management
- Versioned agent IDs (
author/name-version) - Upload validation to reduce risk of malformed packages
Logging and monitoring
- Audit-style events for sensitive actions
- PII redaction principles applied to logs
Data handling
- Vendor list and data flow overview in How we use data
What to request
If you have a questionnaire, send it along with:
- your target use case (support, sales, ops)
- which data classes are involved (PII, PHI, financial)
- whether you need vendor restrictions (model providers)
Quick self-check
- You keep API keys server-side
- You limit prompt content to what’s necessary
- You have a human-in-the-loop step for high-impact actions
Need more detail?
Start in the product, or write to us.