Compliance library

The organizational wrapper around the controls.

Cortex runs one management system across quality, information security and AI. The controls are enforced in code: a hash-chained audit log, a capability policy, and approval gates an agent cannot resolve for itself. These twelve documents are the organisational half of the same system, published in full: each names the code path behind every claim it makes, and each names its own open items rather than omitting them.itting them.

Status vocabularyImplemented enforced in code or CI Documented published, records accrue from first use Partial some of both, remainder named Gap not established
Twelve documents, three bands

An auditor reads both halves.

A control that works but is undocumented is a finding, and so is a policy that is documented but never executed. These documents close the first problem. Only operating them closes the second, which is why every status below is the honest one rather than the flattering one.

Information security

The ISO/IEC 27001 core: scope and applicability, risk, access, incidents, continuity, suppliers, vulnerabilities.

7 documents
AOL-ISMS-001Documented

ISMS scope and Statement of Applicability

The boundary of the information security management system, and a control by control statement of which Annex A controls apply to Cortex, where each one stands and what evidence proves it.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 clause 4; 6.1.3 d)
Open the document
AOL-ISMS-002Documented

Risk register

The information security and AI risks Cortex actually carries, scored with a stated method, treated with controls that point at code, and left with a residual level that somebody owns.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 6.1.2, 6.1.3, 8.2, 8.3
Open the document
AOL-ISMS-003Documented

Access review procedure

The periodic review that confirms the human, agent and machine authority a Cortex stack currently grants is still the authority it should grant.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 A.5.18
Open the document
AOL-ISMS-004Documented

Incident response and breach notification

How an event on a Cortex stack is classified, contained, recovered and reviewed, and what the GDPR and the EU AI Act require once personal data or a high-risk AI system is involved.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 A.5.24 to A.5.28; GDPR Art. 33, 34
Open the document
AOL-ISMS-005Documented

Business continuity and disaster recovery

What a Cortex stack must be able to recover from, in what dependency order, how fast and with how much data loss accepted, together with the two coverage findings that no target in it can hide.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 A.5.29, A.5.30, A.8.13, A.8.14
Open the document
AOL-ISMS-006Documented

Supplier and sub-processor register

The single list of every third party a Cortex stack depends on, what each one can see, which of them are GDPR sub-processors, and what happens when one of them fails.

Owner · CEO RessortAnswers · ISO/IEC 27001:2022 A.5.19 to A.5.23; GDPR Art. 28
Open the document
AOL-ISMS-007Partial

Vulnerability management

How technical vulnerabilities in the five layers a Cortex stack depends on are found, ranked, fixed and excepted, and where that coverage is currently advisory rather than enforced.

Owner · CTO RessortAnswers · ISO/IEC 27001:2022 A.8.8, A.8.25 to A.8.29
Open the document

Conformity-ready, not certified. Every control ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 require is implemented in code or documented as procedure, and the evidence they ask for falls out of normal operation rather than being assembled before an audit. What separates readiness from a certificate is a completed management cycle with its records, an internal audit pass and an accredited certification body: operating work, not engineering work.

Start with the gaps.

The fastest way to judge a management system is to read what it admits. The risk register and the vulnerability procedure are the two documents that say the most about how this one is run.

Risk register Vulnerability management