Cortex

Cortex

Use Cortex to query your program context and speed up navigation, without losing review control.

Cortex

Cortex in the app is /cortex.

Use Cortex when you need fast answers grounded in your Noru data (controls, policies, risks, vendors, evidence) and you want to turn questions into specific next actions.

/cortex starts a conversation. /cortex/[id] loads a saved conversation and its working state. Cortex can use the active organization's framework overview and program records; it can also work with uploaded files within the conversation flow.

What Cortex is good for

  • Finding where you’re blocked (missing owners, stale evidence, unmapped items)
  • Summarizing what exists (e.g. “which controls have no evidence?”)
  • Helping route you to the right page (controls vs evidence vs vendors)

Conversations and generated work

Cortex can propose structured choices and, in supported workflows, draft or edit policy material. Generated policy work still follows the normal policy lifecycle: save, review, approve, version, and export. A chat response is not an approved policy, completed control, accepted risk, or validated evidence item.

When Cortex offers a mutation or generated artifact:

  1. Confirm the active organization and scope.
  2. Inspect the source records and assumptions it cites or summarizes.
  3. Review generated language for claims your organization cannot evidence.
  4. Save into the appropriate source register.
  5. Use normal approval and version history rather than treating the chat as the audit record.

Uploaded files may contain confidential, personal, or customer information. Upload only material authorized for the active organization and avoid secrets that are unnecessary for the question.

How your data is handled

Two commitments govern everything Cortex does with your data. They apply to every organization on every package, and they are contractual — Section 4.6 of the Terms and Sections 3.5–3.6 of the DPA — rather than a setting an administrator has to find and switch off.

  • Your data never trains a model. Nothing you ask, upload, or store in Noru is used to train, fine-tune, or evaluate any AI or machine learning model — Noru's own or a provider's. A conversation in your workspace makes no model better for any other customer.
  • Zero data retention at the model layer. Every model call runs under zero data retention terms: the provider processes the prompt to return the answer and keeps no copy afterwards, nothing is queued for human review, and nothing is retained for training.

Zero data retention describes the model provider, not Noru. Your conversations, uploads, and the records Cortex writes into your program are stored in Noru so you can come back to them, under the retention and deletion terms in the DPA.

Cortex is scoped to the active organization's data, behind the same logical tenant separation as the rest of the platform. Nothing from one workspace carries into another.

What to avoid

  • Don’t ask “how do I get SOC 2?” style questions. Ask about your current state:
    • “Which controls are missing an owner?”
    • “Which evidence items are outdated?”
    • “Which vendors process customer data but have no DPA attached?”

Limitations

Cortex answers depend on current Noru data and available context. It can miss systems outside connected sources, misunderstand ambiguous language, or produce plausible but unsupported recommendations. Verify legal interpretations with counsel and technical facts with system owners. Prefer narrow, state-based questions and ask it to identify the records behind an answer.