This article contains frequently asked questions (FAQs) regarding security.
Q: What measures do you take to protect my data?
A: At CORTO, we implement a robust security strategy to ensure the confidentiality, integrity, and availability of your data. This includes industry-standard encryption, regular scheduled vulnerability assessments, constant security monitoring, and strict access control policies. We utilise trusted cyber security tools for comprehensive threat identification and management. CORTO anonymises data, where possible, to reduce the sensitivity of the information collected.
Data is classified and retained under CORTO’s Data Classification, Handling and Retention Policy. Most user data is retained for seven years. However, matter documents uploaded to the platform are retained for 90 days.
Q: What is the difference between CORTO, Matter AI, and Acctivity.ai?
A: CORTO Pty Ltd (Australia) and CORTO AI Inc. (United States) develop three products. CORTO is our core AI-powered legal platform used directly by law firms, corporate legal departments, barristers, and legal service providers for matter research, drafting, and workflow automation. Matter AI is a plug-in built by CORTO that delivers the same AI capabilities inside an external practice management solution. Acctivity.ai is a standalone AI-powered legal bookkeeping product, also built on the CORTO platform, designed for matter-related bookkeeping and legal accounting automation. All three share CORTO's underlying security architecture and SOC 2 controls.
Q: How is my personal/sensitive information stored?
A: CORTO, Matter AI and Acctivity.ai are cloud-based solutions that store all client data on CORTO Systems, utilising the Amazon Web Services (AWS) platform in the US West (Oregon) region. AWS is a leading cloud provider known for its robust security measures, including advanced identity and access management, encryption, and DDoS protection.
Your personal and sensitive information is securely stored using encryption-at-rest (AES-256). Access to your data within our organisation is tightly controlled and restricted to authorised personnel only.
CORTO follows industry best practices to ensure data security while leveraging AWS's comprehensive security services.
Q: What personal/sensitive data do you collect?
A: CORTO, MatterAI and Acctivity.ai collect the information necessary to provide our services. This includes Personally Identifiable Information (PII) and legal information that users provide to the platform. Any sensitive data is collected with your consent and is used strictly for its intended purpose. Sensitive information may be included as a part of user provided feedback, in the CORTO and Matter AI platforms, which we then use to enhance our services.
Users have the right to request that their data to be deleted from the CORTO, Matter AI and Acctivity.ai platform and backend infrastructure. Communication of this request must be requested through the appropriate channels.
For CORTO and Acctivity.ai users, please contact [email protected].
For Matter AI users, please contact [email protected].
Q: Do you comply with any cyber security frameworks?
A: Yes, CORTO has obtained its SOC 2 Type II certification, a globally recognised security framework developed by the American Institute of Certified Public Accountants (AICPA). The framework encompasses controls for managing customer data, application architecture and business practices, ensuring that CORTO and the applications it develops are secure. Our SOC 2 certification covers the CORTO, Matter AI and Acctivity.ai products.
CORTO is also certified with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF. This framework helps ensure that personal data transferred from the European Union and the United Kingdom to the United States is handled securely and in compliance with privacy regulations. CORTO’s certification with the EU-U.S. DPF with the UK Extension applies to the CORTO, Matter AI and Acctivity.ai products.
Additionally, we follow other industry best practices to maintain the highest security standards across all the applications we develop and their associated systems and processes.
Q: Do you share my data with third parties?
A: We do not share your personal data with third parties unless it is necessary for providing our services or required by law. Our Vendor Management policy ensures any third-party vendors are thoroughly vetted to meet our security and privacy standards.
Q: What data are AI models trained on? Does training data include personal or sensitive information?
A: CORTO does not train its own machine learning or generative AI models. OpenAI and Anthropic's enterprise models used by CORTO’s platforms are trained on a mixture of licensed data, publicly available data, and model provider data sources. Training does not include CORTO, Matter AI or Acctivity.ai client information.
Q: How are staff vetted and trained?
A: All CORTO staff with direct access to our critical infrastructure must undergo a vetting process, including police background checks. This guarantees that only verified team members are entrusted to manage our core platform.
All CORTO staff also participate in mandatory monthly cyber security training modules, ensuring our staff are up to date on the latest cyber safe practices and potential threats.
Q: How do you handle data breaches?
A: In the unlikely event of a data breach, CORTO follows a comprehensive incident response plan. We will notify affected users as required by law, take immediate steps to contain the breach, and conduct a thorough investigation to prevent future incidents. Our team works around the clock to mitigate any risks.
Q: Where can I find CORTO's security statement?
A: CORTO’s security statement is available on our website. You can access it by visiting CORTO - Security Statement.
Q: What should I do if I suspect a security issue with my account?
A: If you suspect a security issue with your account, please contact the CORTO team through our Trust Centre. Our Information Security team will to assist you promptly. We recommend changing your password to enhance security while our team investigates the matter.
Q: Do CORTO’s products use Artificial Intelligence (AI) or Generative AI? If so, how is it used?
A: Yes, CORTO, Matter AI and Acctivity.ai use Generative AI to support selected productivity features within the platform. These features help users document drafting, summarisation, legal research, clause extraction, and workflow automation. CORTO utilises OpenAI and Anthropic for these capabilities, using enterprise grade models and newer successors and are accessed via API calls routed through major cloud providers. These models operate under OpenAI and Anthropic’s privacy commitments, ensuring your data is not used to train or improve their models.
Q: How are AI models selected for use in CORTO’s products?
A: CORTO adopts newly released models for use in the CORTO and Matter AI platforms following an extensive internal testing and evaluation process. This process involves model evaluation by CORTO’s in-house legal team in additional to internally-developed and third-party software designed for model assessment.
The CORTO and Matter AI platforms provide a model selector that determines which model is used to process user prompts. This gives users the ability to choose the model that best suits their needs and to stay current as new models are released.
Q: Are AI features within CORTO product’s operationally dependent on third-party AI systems?
A: Yes, some features within CORTO, Matter AI and Acctivity.ai rely on third-party enterprise infrastructure. Should those services experience disruption, the affected AI features may have temporary reduced functionality. The core platforms remain fully operational and unaffected.
Q: Does CORTO ever send user data outside Australia for AI processing?
A: Yes. CORTO, Matter AI and Acctivity.ai process data in the AWS US West (Oregon) region and use approved third-party AI services operating within the same region. All data is encrypted in transit and protected by privacy safeguards, including strict access controls and assurances that customer data is not used for AI model training.
Q: How is data segmented between customers within CORTO’s platforms?
A: Each customer's data is kept strictly separate from all others. CORTO's systems and infrastructure are designed so that information is only accessible within the customer it belongs to, and cannot be viewed or mixed with another customer's data. This system and infrastructure design is aligned across all CORTO’s platforms; CORTO, Matter AI and Acctivity.ai.
Q: How does CORTO ensure client data confidentiality when using AI?
A: CORTO ensures client data confidentiality through strong encryption in transit (HTTPS/TLS) and at rest, zero training commitments from AI vendors, strict role based access controls, and continuous logging and monitoring. AI providers are isolated and do not have direct access to CORTO's broader data environment. These confidentiality commitments and controls are shared across CORTO, Matter AI and Acctivity.ai.
Q: What data are AI models trained on? Does training data include personal or sensitive information?
A: CORTO does not train its own machine learning or generative AI models. OpenAI and Anthropic's enterprise models used by CORTO’s platforms are trained on a mixture of licensed data, publicly available data, and model provider data sources. Training does not include CORTO, Matter AI or Acctivity.ai client information.
Q: How can users challenge AI outputs or raise concerns about AI use?
A: Users can challenge AI outputs through the built-in CORTO and Matter AI feedback feature or by contacting support. The CORTO team review all concerns promptly and update workflows as needed to maintain accuracy and fairness.
Q: How do you assess AI systems for fairness, accuracy, transparency, and bias and detect and prevent AI Hallucinations?
A: CORTO assesses AI systems, within CORTO, Matter AI and Acctivity.ai, for fairness, accuracy, transparency, bias. This assessment is performed through regular internal audits of AI output quality and continuous monitoring to detect drift, inaccuracies, or unreliable behaviour. For critical or high-risk use cases, human review is performed. Safeguards such as prompt engineering, model constraints, and automated and human output validation are used to reduce the likelihood of hallucinations. There are clear disclosures are provided where AI-generated content is used. Users are encouraged to independently verify AI outputs before relying on them. Users can also provide feedback using the built-in mechanisms in CORTO and Matter AI.
Q: How does CORTO minimise access to client data when using AI?
A: CORTO minimises access to client data through following the principle of least privilege. This includes practices such as Role-Based Access Control (RBAC), quarterly access reviews, need to know restrictions and segregation of duties. CORTO also employs techniques such as data minimisation, encryption at rest and in transit, and comprehensive logging and access auditing for all AI related activities, to further restrict and audit access to this data.
Q: Are AI development and testing environments secured and monitored?
A: Yes. All AI development environments follow CORTO's secure Software Development Lifecycle requirements. This includes the use of segregated environments, access restrictions, secrets management, automated logging and monitoring and regular security assessments for CORTO, Matter AI and Acctivity.ai.
Q: What contingency plans are in place if AI services are unavailable or compromised?
A: CORTO maintains business continuity, incident response and disaster recovery plans and procedures that include monitoring, fallback mechanisms, failover and isolation procedures if any AI services are disrupted. These plans are tested at least annually for all of CORTO’s platforms.