The controls we run, the boundaries we hold, and who owns what between us. If your security team needs more detail than this page carries, ask us for the documentation — we'd rather answer your questions early than late.
The controls in place today, and the team that enforces them.
Customer PII (email, name, birthday) is encrypted in the application, not only on disk, so database access alone does not yield readable PII.
Passkeys and WebAuthn are supported alongside social sign-in and one-time codes. Passkeys and WebAuthn are phishing-resistant by design; the other two methods are not, and we don't claim otherwise.
Code and dependency scanning run automatically on every pull request. Penetration testing is performed on a regular basis by our internal security team.
AI agents run in suggest-mode by default: drafts and recommendations wait for a human. Auto-execution is enabled per workflow, by you.
An internal security team owns these standards across every module and release. Enforcement is automated — every pull request is checked.
Development is held to the OWASP Top 10 as the baseline; verification is against OWASP ASVS.
These are frameworks the platform is built to support, not certifications we hold. Your obligations under them remain yours — section 03 sets out which parts we cover.
Consent records, purpose-of-use boundaries, disclosure, correction, and erasure are platform features rather than custom builds. Meeting your own APPI obligations remains your responsibility.
Architecture, data-flow, and compliance documentation prepared in English for global HQ security reviews and DPO questions.
Security and privacy operations for QORTEX are managed by The Plant K.K., which maintains ISO/IEC 27001 certification and PrivacyMark compliance.
Card details go directly from your customer to your payment gateway — GMO, DGFT, or the provider you already use. QORTEX works from what the gateway returns: a token, an order status, a points movement. Cardholder data is not stored in QORTEX.
Actual PCI DSS scope depends on your integration — redirects, webhooks, and token handling are assessed per deployment, and we'll walk your assessor through ours.
What QORTEX owns outright, what we configure together, and what always remains yours.
| Layer | Owner | What that means |
|---|---|---|
| Cloud infrastructure | QORTEX | Physical and network controls inherited from the cloud providers we run on. |
| Platform runtime & patching | QORTEX | Services, dependencies, and vulnerabilities patched continuously — no action needed from you. |
| Data encryption | QORTEX | Encryption in transit, and application-layer encryption for customer PII. |
| Module configuration & workflows | Shared | We ship hardened defaults and templates; you tailor rules, journeys, and integrations. |
| AI agent autonomy | Shared | Suggest-mode is the default we enforce; promoting an agent to auto-execute is your call, per workflow. |
| Staff accounts, roles & permissions | You | Who on your team can see and do what — roles and permissions are the tool; assignment is yours. |
| Customer consent & purpose of use | You | The platform records and honours consent; defining your purposes under APPI remains your obligation. |
| API keys & integration credentials | You | Credentials for your connected systems are issued to you and managed by you. |
Every copilot, agent, and AI suggestion in the suite runs through the same five checkpoints.
A question or task, in English or Japanese, from the module you're already in.
The agent uses the same APIs and permissions as the signed-in user. It can't read what that user can't.
Inference runs on Google's Gemini Enterprise Agent Platform, inside Google's enterprise security perimeter. Your data is not used to train foundation models.
Agent actions are recorded in the audit log and exportable via API.
Suggest-mode by default: drafts and recommendations wait for a human. Auto-execution exists only where you've promoted it.
Inference runs on Google's Gemini Enterprise Agent Platform (formerly Vertex AI), inside Google's enterprise security perimeter. Your customer data is not used to train foundation models.
An agent uses the same APIs and permissions as the signed-in user, so it cannot read what that user cannot. Suggest-mode is the default, and agent actions are recorded in the audit log.
QORTEX AI is built on the open A2A protocol and is model-agnostic: the underlying LLM can be changed without changing your integration.
Module by module: what's stored, how sensitive it is, and the boundary worth knowing before your security review asks.
| Module | PII | Holds | Boundary worth knowing |
|---|---|---|---|
| Customer Identity | High | Profiles, credentials, consent records | PII fields carry application-layer encryption; consent records export with the data. |
| Product Catalog | None | Product records, attributes, media | Catalog data only — no shopper data lives here. |
| Content Management | None | Pages, assets, brand rules | Content and design-system rules — no shopper data lives here. |
| Order Management | High | Orders, addresses, fulfilment events | Orders reference payment-gateway tokens, not card numbers. |
| Loyalty | High | Points balances, tiers, redemption history | Balances are audit-ready — every movement reconciles to a logged event. |
| Marketing Automation | High | Segments, journeys, delivery & consent state | Sends honour channel consent; opt-outs are enforced platform-wide. |
Client data resides in Japan by default — hosted elsewhere only at your explicit request.
Your customers' data resides in Japan. It's hosted elsewhere only if you explicitly ask us to.
Purpose-of-use boundaries, disclosure, correction, and erasure are platform workflows rather than custom builds.
Export profiles, consent records, and audit trails in open formats, at any time. No proprietary formats and no extraction fees.
Both reach the team that runs the platform.
Report a suspected vulnerability by email. Include steps to reproduce and the affected endpoints, and we'll confirm receipt and keep you updated through the fix.
security@qortex.comSubject: Security report
Security reviews and procurement questionnaires are welcome. Architecture, data-flow, and compliance documentation is available on request, in English or Japanese.
Request documentationWe'd rather answer the hard questions early than late.
A concise overview of QORTEX, its capabilities, and delivery model — specific enough to share with your team and start a real conversation.