Security at Corrobo
Most vendors secure the pipe that carries your data to their cloud. We removed the pipe. Corrobo runs inside a bank's or VASP's own perimeter, on your hardware, under your keys, so the strongest security claim we can make is architectural, not contractual.
Ownership · Control · Evidence
No customer records leave the institution. Models are trained on your dispositions alone: cross-customer training isn't a setting we disable, it's an impossibility. What crosses the perimeter in connected wallet mode, and what never does, is defined precisely below.
Role-based access, SSO, and four-eyes approval enforced by the schema itself. Rules, thresholds and model promotions activate only on your MLRO's signature.
Append-only, hash-chained records of every agent action, human edit and configuration change, reproducible on demand, years later.
The data boundary
Customer identity, KYC records, accounts, transaction-book data, cases, decisions and model outputs never leave the institution, in any mode.
When wallet screening runs in connected mode, exactly one class of data goes out: a public wallet address or transaction hash, already public on-chain, carrying no identity. The provider's risk signal returns, and is joined to a customer only inside your perimeter.
Air-gapped deployments use signed provider-list imports and have no outbound path at all.
Deployment
Choose the model your regulator and security team already accept.
The whole department inside your perimeter, on your hardware.
An isolated environment you control, in a jurisdiction you choose.
No outbound path at all. No release ships without passing the full test suite with networking disabled.
Audit
Each event seals into an append-only chain: who saw the case, what the agent gathered, which rule and model version scored it, who approved it. Export to your SIEM, or hand the regulator the pack.
Reproducibility
Re-run any historical decision under its original rule, model and list versions and receive an identical result: the artifact model-risk teams ask for and agent-first systems cannot produce.
AI Controls
Agents gather the evidence; a deterministic engine makes the call. When the rules are confident, the model is never invoked at all.
Every AI-written claim carries a citation, or carries a flag.
Customer-facing requests use bank-approved templates only.
Prompts and packs are versioned artifacts under change control.
No supporting record: flagged, never asserted.
Assurance
On-premises deployments inherit your perimeter, monitoring and key management today. We publish our roadmap rather than imply certifications we haven't earned, the same discipline we apply to every number on this site.
Architecture, data-flow maps and deployment options: answered before the pilot.
Found something? Report security issues to contact@corrobo.ai. We acknowledge within 2 business days and keep you informed through to resolution.