Home
SolutionsDifferentiatorsDelivery ModelTrustAboutContact 日本語
Trust & Security

How we protect
your customers' data.

The controls we run, the boundaries we hold, and who owns what between us. If your security team needs more detail than this page carries, ask us for the documentation — we'd rather answer your questions early than late.

01 / Platform security

What protects your data.

The controls in place today, and the team that enforces them.

Application-layer PII encryption

Customer PII (email, name, birthday) is encrypted in the application, not only on disk, so database access alone does not yield readable PII.

Passwordless sign-in

Passkeys and WebAuthn are supported alongside social sign-in and one-time codes. Passkeys and WebAuthn are phishing-resistant by design; the other two methods are not, and we don't claim otherwise.

Continuous verification

Code and dependency scanning run automatically on every pull request. Penetration testing is performed on a regular basis by our internal security team.

AI actions require sign-off

AI agents run in suggest-mode by default: drafts and recommendations wait for a human. Auto-execution is enabled per workflow, by you.

Who enforces it

A staffed security function

An internal security team owns these standards across every module and release. Enforcement is automated — every pull request is checked.

OWASP, both layers

Development is held to the OWASP Top 10 as the baseline; verification is against OWASP ASVS.


02 / Compliance

Frameworks the platform supports.

These are frameworks the platform is built to support, not certifications we hold. Your obligations under them remain yours — section 03 sets out which parts we cover.

APPI

Japan's Act on the Protection of Personal Information

Consent records, purpose-of-use boundaries, disclosure, correction, and erasure are platform features rather than custom builds. Meeting your own APPI obligations remains your responsibility.

GDPR

Documentation for global review

Architecture, data-flow, and compliance documentation prepared in English for global HQ security reviews and DPO questions.

Security and privacy operations for QORTEX are managed by The Plant K.K., which maintains ISO/IEC 27001 certification and PrivacyMark compliance.

Payment data

Architected to minimize PCI DSS scope.

Card details go directly from your customer to your payment gateway — GMO, DGFT, or the provider you already use. QORTEX works from what the gateway returns: a token, an order status, a points movement. Cardholder data is not stored in QORTEX.

Actual PCI DSS scope depends on your integration — redirects, webhooks, and token handling are assessed per deployment, and we'll walk your assessor through ours.


03 / Shared responsibility

Who is responsible for what.

What QORTEX owns outright, what we configure together, and what always remains yours.

Layer Owner What that means
Cloud infrastructure QORTEX Physical and network controls inherited from the cloud providers we run on.
Platform runtime & patching QORTEX Services, dependencies, and vulnerabilities patched continuously — no action needed from you.
Data encryption QORTEX Encryption in transit, and application-layer encryption for customer PII.
Module configuration & workflows Shared We ship hardened defaults and templates; you tailor rules, journeys, and integrations.
AI agent autonomy Shared Suggest-mode is the default we enforce; promoting an agent to auto-execute is your call, per workflow.
Staff accounts, roles & permissions You Who on your team can see and do what — roles and permissions are the tool; assignment is yours.
Customer consent & purpose of use You The platform records and honours consent; defining your purposes under APPI remains your obligation.
API keys & integration credentials You Credentials for your connected systems are issued to you and managed by you.
You always retain
Your customer data and what it's used for
Your staff's access
Your consent obligations to your customers
04 / AI & your data

How AI handles your data.

Every copilot, agent, and AI suggestion in the suite runs through the same five checkpoints.

Gemini Enterprise Agent Platform No foundation-model training Same permissions as your team Audit-logged
  1. Step 01

    You ask

    A question or task, in English or Japanese, from the module you're already in.

  2. Step 02

    Permissions apply

    The agent uses the same APIs and permissions as the signed-in user. It can't read what that user can't.

  3. Step 03

    Inference, not training

    Inference runs on Google's Gemini Enterprise Agent Platform, inside Google's enterprise security perimeter. Your data is not used to train foundation models.

  4. Step 04

    Actions are logged

    Agent actions are recorded in the audit log and exportable via API.

  5. Step 05

    You sign off

    Suggest-mode by default: drafts and recommendations wait for a human. Auto-execution exists only where you've promoted it.

The questions enterprise reviews ask first
Q · Is our data safe?

It stays inside Google's enterprise perimeter.

Inference runs on Google's Gemini Enterprise Agent Platform (formerly Vertex AI), inside Google's enterprise security perimeter. Your customer data is not used to train foundation models.

Q · Can we trust it?

Your permissions apply, and a human signs off.

An agent uses the same APIs and permissions as the signed-in user, so it cannot read what that user cannot. Suggest-mode is the default, and agent actions are recorded in the audit log.

Q · Will it last?

Open protocol, model-agnostic.

QORTEX AI is built on the open A2A protocol and is model-agnostic: the underlying LLM can be changed without changing your integration.

05 / Data map & sovereignty

What each module holds, and where it lives.

Module by module: what's stored, how sensitive it is, and the boundary worth knowing before your security review asks.

Module PII Holds Boundary worth knowing
Customer Identity High Profiles, credentials, consent records PII fields carry application-layer encryption; consent records export with the data.
Product Catalog None Product records, attributes, media Catalog data only — no shopper data lives here.
Content Management None Pages, assets, brand rules Content and design-system rules — no shopper data lives here.
Order Management High Orders, addresses, fulfilment events Orders reference payment-gateway tokens, not card numbers.
Loyalty High Points balances, tiers, redemption history Balances are audit-ready — every movement reconciles to a logged event.
Marketing Automation High Segments, journeys, delivery & consent state Sends honour channel consent; opt-outs are enforced platform-wide.
Data sovereignty

Client data resides in Japan by default — hosted elsewhere only at your explicit request.

Japan by default

Your customers' data resides in Japan. It's hosted elsewhere only if you explicitly ask us to.

Governed by APPI

Purpose-of-use boundaries, disclosure, correction, and erasure are platform workflows rather than custom builds.

Export on exit

Export profiles, consent records, and audit trails in open formats, at any time. No proprietary formats and no extraction fees.


06 / Disclosure & documentation

Security reviews and vulnerability reports.

Both reach the team that runs the platform.

Report a vulnerability

Report a suspected vulnerability by email. Include steps to reproduce and the affected endpoints, and we'll confirm receipt and keep you updated through the fix.

security@qortex.com

Subject: Security report

Request security documentation

Security reviews and procurement questionnaires are welcome. Architecture, data-flow, and compliance documentation is available on request, in English or Japanese.

Request documentation

Bring your security team.

We'd rather answer the hard questions early than late.

Get a personalised demo → Get the overview as a PDF

Get the Introduction to QORTEX

A concise overview of QORTEX, its capabilities, and delivery model — specific enough to share with your team and start a real conversation.