Security at Corrobo

Nothing leaves the bank.

Most vendors secure the pipe that carries your data to their cloud. We removed the pipe. Corrobo runs inside a bank's or VASP's own perimeter, on your hardware, under your keys, so the strongest security claim we can make is architectural, not contractual.

Your perimeter. No customer-data egress.

Ownership · Control · Evidence

Your data, your models

No customer records leave the institution. Models are trained on your dispositions alone: cross-customer training isn't a setting we disable, it's an impossibility. What crosses the perimeter in connected wallet mode, and what never does, is defined precisely below.

Authority stays human

Role-based access, SSO, and four-eyes approval enforced by the schema itself. Rules, thresholds and model promotions activate only on your MLRO's signature.

Every decision replays

Append-only, hash-chained records of every agent action, human edit and configuration change, reproducible on demand, years later.

The data boundary

What crosses the perimeter, precisely.

Customer identity, KYC records, accounts, transaction-book data, cases, decisions and model outputs never leave the institution, in any mode.

When wallet screening runs in connected mode, exactly one class of data goes out: a public wallet address or transaction hash, already public on-chain, carrying no identity. The provider's risk signal returns, and is joined to a customer only inside your perimeter.

Air-gapped deployments use signed provider-list imports and have no outbound path at all.

Deployment

Three ways to run it. None of them ours.

Choose the model your regulator and security team already accept.

On-premises

The whole department inside your perimeter, on your hardware.

Sovereign cloud

An isolated environment you control, in a jurisdiction you choose.

Air-gapped

No outbound path at all. No release ships without passing the full test suite with networking disabled.

SOVEREIGN MODELS · FALCON · JAIS · SARVAM

Audit

Every action, on the record.

Each event seals into an append-only chain: who saw the case, what the agent gathered, which rule and model version scored it, who approved it. Export to your SIEM, or hand the regulator the pack.

Reproducibility

Same inputs. Same verdict. Byte for byte.

Re-run any historical decision under its original rule, model and list versions and receive an identical result: the artifact model-risk teams ask for and agent-first systems cannot produce.

AI Controls

The model never decides.

The engine decides

Agents gather the evidence; a deterministic engine makes the call. When the rules are confident, the model is never invoked at all.

Cited or flagged

Every AI-written claim carries a citation, or carries a flag.

Bank-approved templates

Customer-facing requests use bank-approved templates only.

Versioned & change-controlled

Prompts and packs are versioned artifacts under change control.

No supporting record: flagged, never asserted.

Assurance

What we hold today, and what we don't yet.

On-premises deployments inherit your perimeter, monitoring and key management today. We publish our roadmap rather than imply certifications we haven't earned, the same discipline we apply to every number on this site.

SOC 2 TYPE II · IN PROGRAMME PENETRATION TEST · SCHEDULED ISO 27001 · PLANNED

Send us your security questionnaire.

Architecture, data-flow maps and deployment options: answered before the pilot.

Found something? Report security issues to contact@corrobo.ai. We acknowledge within 2 business days and keep you informed through to resolution.