SECURITY & GOVERNANCE

Corin sees only what your login sees.

It inherits your existing SAP and Infor permissions — and never grants new ones. Read-only until you approve.

One action, one token — scoped to the minimum, expiring after the call, logged in the ledger.
your loginSAP · Infor roles
identity providerOAuth 2.0
scoped tokenscope: quote.write · 90s
one tool callAPI_SALES_ORDER_SRV
token expiresrevoked · ledgered

Token and scope shown are illustrative; real scopes come from your identity provider.

AI agent security, one scoped token at a time.

Corin never forwards your credentials. Every tool call uses a short-lived token scoped to the minimum permission that one action needs — issued in your name, logged in the ledger: what changed, who approved it, when.

NAMED ATTACKS, NAMED CONTROLS

Three failure modes. Three controls.

Not "hardened" — specific. The three failure modes that break agent deployments, and the control that answers each.

Tool poisoning & prompt injection
the allowlisted catalog
Tools come only from Corin's allowlisted, certified catalog — no dynamic discovery of unknown servers. A tool that isn't certified into the catalog does not exist at runtime.
Missing auth
OAuth per connection, identity binding
Every connection authenticates with OAuth and is bound to your tenant's identity. A token from one tenant cannot call in another's name — the binding is checked on every request.
Runaway writes
thresholds and receipts
Approval thresholds cap what can post without a person — per workflow, per amount, per counterparty. The receipt is written before the ERP transaction: if the write happens, the record already exists.
THE UNTRUSTED BOUNDARY

Security that assumes the inbox is hostile.

Corin reads the messages your attackers can also send. A message can influence what Corin extracts — never what Corin is allowed to do.

01

Prompt-injection isolation

Instructions embedded in an email or PDF have no path to execution. Inbound content is parsed as untrusted data inside an isolated boundary — it is never concatenated into authority.

02

Policy-derived tool selection

Which tools exist for a run derives from policy and workflow state only — never from model output or message content. Allowlists are set per module, per tenant.

03

Scanned and schema-constrained

Attachments are malware-scanned, and extraction is schema-constrained: a hostile PDF cannot smuggle in structure Corin never asked for.

FIELD-LEVEL PROVENANCE

Every extracted field carries its receipt.

Every consequential extraction records where the value came from — message, attachment hash, page, region, source text — plus the extractor version and confidence. A dispute becomes a lookup, not an argument.

PROVENANCE RECORD — SPECIMEN
ISOLATION & CREDENTIALS

Least privilege, tested — not promised.

Isolation tested in CI, checked at runtime

Cross-tenant access is not a policy promise — it is a test suite in CI and a check the engine runs on every request. One customer's data never warms up another customer's answers; a breach of isolation is an error, not an incident report.

Split connector credentials

Read and write credentials are separate, least-privilege, and scoped per connector. A read path can never write.

Per-action authorization

Every consequential action is authorized individually — signed approval records, dual control where policy demands it.

DATA BOUNDARY

Provable, not promised.

Inventory per deployment form
A formal data inventory exists for each delivery form — hosted, private connector, BYOC, air gap. "Only metadata reaches the control plane" is provable, not promised.
No training without agreement
Your operational data is never used to train models without an explicit agreement. Learning happens inside your tenant, on your outcomes.
Self-hosted, air gap included
The engine under Corin can run entirely inside your walls — including with the internet cable unplugged.
Audit export — SIEM and WORM
The append-only ledger exports to your SIEM and to WORM storage, so the record of what happened survives independent of Corin.
Emergency connector revocation
Incident response includes a kill switch: one control severs the platform's path to your ERP — instantly, and the revocation itself is ledgered. Disconnect anytime; every action stays on the record.
PRIVATE INFERENCE

Bring your own compute. Keep your boundary.

Corin's router decides which model runs each step. Where those models run can be entirely your call: your Azure OpenAI deployment, your Amazon Bedrock account, your Vertex AI project, or a model behind your own firewall. Prompts and documents go to endpoints you own, under your cloud agreements — and locked to private mode, Corin fails closed rather than falling back to anyone's cloud.

Your data agreements

Inference in your tenancy inherits your provider terms: Azure's models are stateless and your prompts are not available to OpenAI; Bedrock never shares inputs with model providers; zero-data-retention terms apply where you've negotiated them.

Your accredited boundary

Azure OpenAI is approved under FedRAMP High and DoD IL4/IL5 in Azure Government. Claude in Amazon Bedrock carries the same approvals in AWS GovCloud. Corin runs inside the boundary you already accredited — it doesn't borrow the badge.

Your keys, write-only

Bring your own keys and endpoints — accepted, stored encrypted, and never returned by any API. Access is governed by your cloud's IAM, and traffic can stay on your private endpoints.

EXPORT-CONTROLLED WORK

Keep technical data on U.S. soil, with U.S. persons.

No vendor is "ITAR certified" — no such certification exists, and compliance stays yours. What Corin does instead: route inference into AWS GovCloud or Azure Government, where infrastructure sits on U.S. soil and is administered by screened U.S. persons, so export-controlled technical data is processed inside an environment you control. Your boundary, your authorization — Corin operates under it, never in place of it.

ACCESS CONTROL

Who can approve what.

Role-based access down to the decision type and entity. The same matrix governs the app, the API, and the MCP tools.

Sales rep

Run dry runs and read decision cardsown accounts
Approve quotes up to $25kledger entry written
Approve quotes above $25kroutes to manager
Change autonomy levelsadmin only

Sales manager

Approve quotes up to $100kledger entry written
Override the margin floordual control
Edit team policy boundsversioned
Post payments or move moneynever an app action

Finance controller

Approve credit memosledger entry written
Release a credit holddual control
Set entity-level autonomywith admin
Export the audit ledgerread-only

Matrix shown is the design baseline; your tenant configures its own.

THE AUDIT LEDGER

Complete traceability, COSO-friendly.

Model and version, prompts and inputs, reasoning, the human who confirmed, and the postings that resulted — retained and queryable. When the auditor asks "why did this happen", the answer is a lookup, not an interview.

The ledger as the artifact itself — every row names its actor, its gate, and its outcome.
timeactoractionidgatestatus
09:14:07corinQuote sent — quotation 20005731 filed in SAPf03d…8b1cpolicyapproved
09:14:02m.chenQuotation 20005731 approved and releasedreceipt written before the ERP writea41f…9c2ehumanapproved
09:12:47policy:margin-floorQuote held — price below floorwaiting on human review7bd2…e410policypending
08:47:30j.okaforTerms override rejected — outside policydual control5e19…d044humanrejected

Illustrative ledger rows — sample data, not a customer record.

THE GUARANTEE

Corin never moves money, signs, or sends without your confirmation — until you tell it to.

Autonomy levels are explicit, per decision type, and changeable at any time. Autopilot is bounded by policy you write — value limits, counterparties, terms ranges — and still logs everything.

EU AI ACT

Scoped, not hand-waved.

Corin supports human decisions in sales and finance operations; it is not credit scoring, biometric, or critical-infrastructure AI under the Act's high-risk annexes.

Human sign-off gates, logging, and versioning are built to make your conformity assessments straightforward. We track the Act's timeline and will update this page as guidance lands — this is a scoping statement, not legal advice.

COMPLIANCE PROGRAM

Named milestones, in sequence.

01SOC 2 Type II

Audit engagement is the first compliance milestone after general availability.

02Microsoft 365 Certification

Targeted with the Teams approval surface.

03Marketplace listings

SAP Store and Infor Marketplace listings follow their respective certification processes.

DECISIONS, WITH RECEIPTS

See what Corin will do before it does it.