Self-hosted · Air-gap capable · Zero data exodus

Run every system. Show one interface. Prove every action.

Cortex is a sovereign, self-hosted AI control plane that connects to the enterprise systems you already run — Maximo, SAP, Salesforce, Snowflake, your databases — and replaces their interfaces with a single natural-language workspace. Every agent action is cryptographically signed and Merkle-chained. Nothing ever leaves your infrastructure.

WCAG 2.2 AA EU AI ACT ART.12 NERC CIP-015-1 IETF SCITT SOC 2-READY ED25519 SIGNED
Provenance Ledger — live capsule stream verifying
postgres_list_tables
blake3:8f3a0c…e91c
agent: gw-04✓ ed25519
cdc_mirror.commit
blake3:2b71fa…0a4d
agent: mirror-1✓ ed25519
absorb.field_promote
blake3:c40d91…77b2
agent: absorb-2✓ ed25519
genesis.render_panel
blake3:5e1209…9f3a
agent: genesis-1✓ ed25519
scitt.anchor_receipt
blake3:a9c7d4…11e8
agent: prov-0✓ ed25519
retire.sign_cert
blake3:7140bd…c62f
agent: retire-1✓ ed25519
postgres_list_tables
blake3:8f3a0c…e91c
agent: gw-04✓ ed25519
cdc_mirror.commit
blake3:2b71fa…0a4d
agent: mirror-1✓ ed25519
absorb.field_promote
blake3:c40d91…77b2
agent: absorb-2✓ ed25519
genesis.render_panel
blake3:5e1209…9f3a
agent: genesis-1✓ ed25519
scitt.anchor_receipt
blake3:a9c7d4…11e8
agent: prov-0✓ ed25519
retire.sign_cert
blake3:7140bd…c62f
agent: retire-1✓ ed25519
Every capsule is BLAKE3-hashed, parent-linked, and Ed25519-signed — 0 Merkle failures across 1M capsules in validation.
≤10MB
SINGLE BINARY
≤50ms
P95 ROUTING LATENCY
4GB / 2vCPU
MIN. FOOTPRINT
100%
WCAG 2.2 AA — 18 COMPONENTS
99.9%
GATEWAY UPTIME TARGET
Why Cortex

Three problems most enterprise AI projects never solve.

Most "AI for the enterprise" platforms either route your data to a vendor cloud, bolt a chatbot onto existing screens, or hand you a governance dashboard with nothing underneath it. Cortex was built around three constraints that don't compromise.

01

Sovereignty by construction

Cortex is a single Rust binary plus PostgreSQL with pgvector — nothing else. It runs on your server, validates its license offline via Ed25519-signed JWT, and never makes an outbound call. Defence, banking, and energy customers can run it fully air-gapped with updates delivered on physical media.

02

Provenance, not promises

Every agent action — every query, every write, every dashboard generated — produces a BLAKE3-hashed, Ed25519-signed TraceCaps capsule, chained into a Merkle tree and anchored to IETF SCITT. The result is an IETF AAT-compliant audit trail that satisfies EU AI Act Art. 12 and NERC CIP-015-1 out of the box.

03

Migration nobody notices

Cortex doesn't ask anyone to switch tools. It observes how your teams already work inside Maximo, SAP, or Salesforce, mirrors the underlying data in real time, and gradually generates a faster, accessible interface behind a Strangler Fig façade — with instant rollback to the legacy app if anything doesn't match.

The Obsolescence Pipeline

Six phases. Zero downtime. Zero detection.

Cortex migrates a workload from legacy software to a Cortex-native, accessible dashboard through a fixed sequence. Each phase is independently reversible, and each one produces its own cryptographic record.

01
ObserveField-level capture

A lightweight browser extension and ObserverAgent record field-level interactions inside your existing applications, building decision traces without changing a single workflow.

02
MirrorReal-time CDC

Once a field is observed often enough, the Mirror Engine subscribes to the source database's change stream — column-level, Kafka-free — and replicates it into TraceDB with sub-100ms p95 latency at 250M+ events/week.

AbsorbJust-in-time promotion
03

The Absorption Engine promotes mirrored fields into agent-safe, copy-on-write branches, gated by a write-approval step — so Cortex can act on the data without ever risking the source of truth.

04
GenesisSelf-building UI

The Genesis Engine converts absorbed fields and observed workflows directly into WCAG 2.2 AA A2UI dashboards — behaviourally equivalent to the screens your teams already know, just faster and accessible.

05
ReplaceStrangler Fig façade

Live traffic is progressively routed to the new Cortex panels. An absorption-score dashboard shows leadership exactly how much of each system has been replaced, with instant hybrid rollback to the legacy app at the same workflow step if needed.

06
RetireCryptographic decommission

The Retirement Engine captures full context, replays it for functional equivalence, and signs a cryptographic decommissioning certificate — your evidence that the legacy system can be switched off.

Security Fortress

Seven layers of defence. One switch to stop everything.

Cortex assumes zero implicit trust between any two components. Every MCP request — from a user, an agent, or another system — passes through the full stack before it can touch a connector.

Semantic FirewallBlocks OWASP MCP Top 10 prompt-injection patterns before routing
L1
Tool-Level RBACPer-tool, per-role authorisation on every connector
L2
Crypto HITLEd25519 manifest signing for high-risk operations
L3
CABP Identity Pipeline6-stage token, scope, entitlement and rate-limit checks
L4
MCPShieldProbe → constrained execution → post-invocation reflection
L5
MCIP Contextual IntegrityValidates sender identity, context and consent
L6
Greybox Semantic FuzzerContinuously probes for unauthorised state transitions
L7
EU AI Act Art. 12 NERC CIP-015-1 SOC 2 IETF SCITT IETF AAT WCAG 2.2 AA / VPAT 2.4

CortexGuard — offline kill switch

A single administrator action halts every agent in the system, instantly and verifiably — even with no network connectivity. Recovery is just as immediate.

POST /admin/kill  →  503 on every subsequent /mcp request
POST /admin/revive  →  200 resumes, fully audited

Built on a hardware-token, behavioural-baseline and network-heartbeat model — works identically whether you're online or fully air-gapped.

Integrations

Connects to what you've already got.

Cortex ships with MCP connectors for the systems most enterprises already run, with new connectors added continuously. No vendor-specific runtime dependencies are required for backup parsing.

IBM Maximo
Oracle E-Business Suite
Oracle Fusion Cloud
SAP S/4HANA
Salesforce
Workday
Snowflake
Jira
GitHub Enterprise
Slack
ServiceNow
PostgreSQL
SQL Server
IBM DB2
Deployment

Three tiers of sovereignty. You choose where the line sits.

Every tier runs the same binary and the same provenance engine. The only difference is where the infrastructure — and the keys — live.

Tier A — Managed Sandbox

Evaluation Demo

Hosted / for evaluation only
  • Cortex hosted on a managed instance
  • Sample Knowledge Snap + demo data
  • Full Insight Engine + dashboard preview
  • No production data permitted
  • Up to 2 connectors configured for you
Launch the demo
Tier C — Air-Gapped

Regulated & Defence

Custom / site licence + media bundle
  • No connectivity to Cortex infrastructure, ever
  • Offline Ed25519 license validation
  • Updates via signed physical-media bundles
  • DORA, PQFIF, NCSC & NIST PQ compliance agents
  • Dedicated implementation & runbook support
Talk to us
Partners & Validation

Built to validate against the infrastructure you already trust.

Cortex's self-validation suite runs twelve independent experiments — security, semantic routing, provenance integrity, mobile inference and more — and produces a signed, reproducible AnalysisReport.

Dell AI Factory reference architecture

Cortex's deployment model is validated against Dell PowerEdge XE servers with NVIDIA NemoClaw, producing a due-diligence report and deployment blueprint for direct submission through the Dell AI Ecosystem Program.

View validation report

Become an implementation partner

Systems integrators, MSPs and compliance consultancies can deliver Cortex deployments using the Implementation Manual and a structured Phase 0–6 launch plan. Partner enablement includes access to the Knowledge Snap library and connector SDK.

Apply to partner
Pricing

Licensed by node, not by seat.

Because Cortex replaces software rather than adding to it, pricing is structured around infrastructure footprint and connector count — not per-user fees that punish adoption. Every plan includes the full Security Fortress and provenance engine.

Pilot

Single Department

Contact us / 90-day pilot
  • One production node
  • Up to 4 connectors
  • Absorption Pipeline for one workload
  • Email support, 1 business day SLA
Start a pilot
Air-Gapped / Regulated

Mission-Critical

Contact us / site licence
  • Physical-media update bundles
  • DORA / PQFIF / NCSC / NIST PQ agents
  • Dedicated implementation engineer
  • On-site or classified-environment support
Request pricing
Resources

Everything you need to evaluate, deploy and run Cortex.

Documentation is versioned alongside every release and ships inside the air-gap bundle, so your teams never need external access to read it.

Download

Cortex Binary & Air-Gap Bundle

Single static Rust binary (≤10MB), Docker image, or a complete offline .tar.gz bundle with binary, config, Knowledge Snap and migrations.

Download latest release →
Manual

User Manual

How to use the Interface of One — natural-language queries, dashboards, the command bar, and the Provenance Explorer for compliance teams.

Read the user manual →
Manual

Implementation Manual

The full Phase 0–6 launch runbook: install, connector configuration, the Absorption Pipeline, validation suite, and air-gap deployment procedures.

Read the implementation manual →
Demo

Live Demo

Explore a hosted Cortex instance pre-loaded with a Knowledge Snap for your industry — energy & utilities, banking, or general enterprise.

Launch the demo →
Partners

Partner Programme

Apply for implementation-partner enablement, including the connector SDK, Knowledge Snap library, and joint validation reports.

Apply to the partner programme →
Pricing

Pricing & Licensing

Per-node licensing across Pilot, Sovereign Enterprise and Air-Gapped tiers, with a guided consultation to size your deployment.

View pricing →
Early access

Replace your stack. Don't disrupt anyone.

Talk to the team building Cortex about a 90-day pilot on one workload — fully reversible, fully audited, and run entirely inside your own infrastructure.