Security & Assurance

MRCortex AI Trust Infrastructure

Built to be audited. Honest about maturity.

This page is for CISOs, security engineers, enterprise architects and technical evaluators. It explains how MRCortex is engineered for governed, evidenced AI activity — and states plainly what is implemented and tested today and what is still being completed for Customer-Ready V1.

— Deterministic governance

Decisions, not heuristics.

SARVA is the deterministic governance layer. Supported governed requests are evaluated through SARVA’s five-gate governance pipeline against explicit controls, authority context and organizational policy, and resolved to allow, escalate or block, with the decision recorded.

Monitoring observes activity after the fact. Governance evaluates a supported request against policy before it proceeds on the supported path. Traditional monitoring alone does not answer what an AI was allowed to do.

Five gates, named at a high level

Ethics · Capability · Sandbox · Guard · Irreversibility / Authority Boundary

— Authority separation

Capability does not confer authority.

Capability

what it can do

≠Authority

what it may invoke

≠Permission

what policy allows

An AI may be technically capable of an action without being authorized to perform it — and authorization is not the same as being permitted by policy. SARVA keeps an AI’s proposal structurally separate from execution authority.

Authority is treated as context to be established, not assumed: it is not presumed to last indefinitely, it does not automatically pass from one agent or step to the next, and it is designed not to expand silently as requests move through supported agents, services and workflows.

— Design philosophy

When permission cannot be confirmed, the design intent is that it does not proceed.

MRCortex is designed fail-closed: where a supported request cannot be confirmed as permitted by policy and authority context, the intended outcome is that it does not proceed on the supported path, and the decision is recorded.

This describes design intent for the governance architecture. The enforced consequential-execution architecture required for Customer-Ready V1 is designed and technically frozen and is being completed; MRCortex does not claim that every consequential action is currently intercepted in production.

— Evidence integrity

A record you can verify, not one you are asked to trust.

Integrity-protected

Governed decisions and relevant events are recorded in a hash-linked (SHA-256) trail. Modifications are detectable.

Policy-version traceable

Each governed decision is linked to the policy version in force at the time.

Reviewable and exportable

Records are exportable and verifiable by authorized reviewers; recorded decisions, events and changes can be reconstructed for review.

Evidence is not permission. COSMOS does not grant execution authority, and integrity evidence does not by itself establish the real-world outcome of an external action.

— Human oversight

People stay in the governance process where required.

Escalated decisions require human approval with recorded justification. Escalation is a first-class outcome of the pipeline, not an exception path.

— Adversarial engineering

Challenged from source code during development.

The architecture and implementation are subjected to internal adversarial engineering review, including read-only independent-model review used during development, to surface weaknesses before a release candidate is frozen.

MRCortex does not currently claim an independent security audit, third-party audit, external assessment or certification.

— Automated verification

Verified engineering progress.

9,208

registered automated engineering checks

0

failures at M5-R1 closure evidence d5284fe

86

environment-skipped checks reported separately and not counted as passed

Registered automated engineering checks verified against the M5-R1 closure evidence state — not a certification, external validation or independent assurance claim, and not proof of universal security.

Customer-Ready V1 in development

— External assessment roadmap

Preparing for external assurance.

MRCortex is designed with enterprise assurance requirements in mind and is preparing for external assurance. Until such an assessment is complete, MRCortex makes no claim of a completed external assessment.

Mapped or being mapped to relevant frameworks. This is alignment, not certification: MRCortex does not currently claim SOC 2 certification, ISO certification or regulatory approval.

EU AI ActNIST AI RMFISO 42001ISO 27001GDPR alignment, not certification
— Known boundaries

What is implemented. What is not yet. What we do not claim.

Implemented and tested

  • A provider/runtime-agnostic Discovery foundation that identifies and characterizes AI through supported discovery mechanisms, with explicit UNKNOWN states.
  • The SARVA five-gate governance pipeline for supported requests.
  • Architectural separation of an AI’s proposal/capability from execution authority.
  • COSMOS integrity-protected, hash-linked evidence with verification mechanisms.
  • Engineering for understanding how AI systems may reach tools, services, credentials and consequential resources, described here only at a high level.

Being completed for Customer-Ready V1

  • The enforced consequential-execution architecture: designed and technically frozen, not yet implemented end-to-end.
  • Customer-Ready V1 itself. MRCortex is not yet Customer-Ready V1 and does not describe the platform as enterprise-ready, production-ready, certified or fully deployed.

What we do not claim

  • Universal compatibility, or that every AI technology has been validated.
  • That every consequential action is currently intercepted.
  • Immutable or tamper-proof evidence.
  • That evidence proves the real-world outcome of an external action.
  • Enterprise-ready, production-ready, certified or fully deployed status.
  • A completed external assessment.

Unknown ≠ malicious. Known ≠ trusted. Discovery ≠ permission. Registration ≠ authority.

— Overview

Architecture Overview

This site describes MRCortex at a conceptual level; detailed implementation mechanics are intentionally not published. Technical architecture, governance model and engineering evidence for MRCortex AI Trust Infrastructure are available on request.

Request the overview

Engineering toward Customer-Ready V1.