Cortex AI
Cortex AI is an embedded intelligence layer within the CorityOne platform. It uses task-specific AI agents to automate manual EHSQ processes such as scanning handwritten inspections, analyzing incident photos, and extracting permit requirements.
Features
- AI-Powered Incident Scanning
- Automated Permit Requirement Extraction
- Predictive Risk Analytics
- Centralized AI Governance Hub
- Document Processing
Benefits
- Automation
- Proactive risk prevention
- Accelerate decision-making
- Digitize handwritten forms instantly
- Detect workplace hazards autonomously
- Streamline compliance
- Improve investigation accuracy
- Centralize AI governance
- Enhance workforce engagement
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 3 9 6 2 1 1 8 9 6 6 0 9 8 9
Contact
Cority Software
Stacey Hertzman
Telephone: +44 1978 772035
Email: stacey.hertzman@cority.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- CorityOne
- Cloud deployment model
- Public cloud
- Service constraints
- In order to use the software, end users must have access to a modern web browser and electronic device that meets the minimum technical requirements.
- System requirements
-
- Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari.
- Internet Connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Please see our SLA: https://www.cority.com/legal-center/service-level-agreement/
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Please see our SLA: https://www.cority.com/legal-center/service-level-agreement/
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- An implementation project with various stages will get the system set up for your organisation. At the beginning of the project orientation training will be provided to the client project team for solution setup, including navigation, workflows, demographic data, organizational structure and settings to support the Client's team understanding of the Essentials package. User accounts will be set up for the system users during the project. General system context sensitive help is available via the in application help tools. During the project the client team will be responsible to create Client specific guides or tip sheets.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- The first option at no cost is for the Client to extract their data via reports. The second and third options include either a backup of the full database or an extract of data files for an additional cost. Clients can opt to have documents extracted in their native format at an additional cost.
- End-of-contract process
- Client will notify in writing to Cority that they would like to terminate the contract. Cority and Client will then agree to the method for data extraction. Pricing will be determined in a Statement of Work prepared by Cority and agreed to and signed by both parties.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Via email but also via our on-line Cority User Community
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile functionality is complementary and intended to supplement the desktop service.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- See Cority documentation
- Accessibility standards
- None or don’t know
- Description of accessibility
- Like many other SaaS vendors, although we cant guarantee 100% accessibility compliance at all times, we exercise commercially reasonable efforts to design and to maintain our platform to be substantially compliant with WCAG standards. We proactively resolve issues, conduct regular automated audits, and embed accessibility testing into our engineering processes.
- Accessibility testing
- To be verified
- API
- Yes
- What users can and can't do using the API
- The Cority API is the most robust API available in our industry. It is capable of processing enormous volumes of data including hundreds of thousands of data points (that are used in calculations instantly). Furthermore, it routinely handles tens of thousands of transactions in a single day for complex workflows with dozens of fields per record. Unlike many competitive solutions, the Cority API is central to ALL user activities in the system as ALL of the end-user experience provided in our Portal and Apps communicate with our database using the exact same API (and endpoints) we make fully available to our customers. . In addition to simply importing records, the API also extends to the administration of the system. Nearly all of the platform, including configuration tasks, can be achieved through the use of the API. This includes managing the hierarchy, managing assets, managing users, managing user groups, managing dashboards and dashboard permissions, managing streams/materials, workflow types, and much much more. Finally, extracting data from the system using the API is also very powerful. Customers routinely use the EQL API (similar to SQL with the same syntax) to extract data and put that information in data lakes.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Cority is extremely "configurable" to allow customisation to specific organisational needs. Most dashboards, reports and fields can be adjusted with no-code. There are specific configuration components that will allow for client inputs during the implementation of the package outlined in the statement of work in the referenced documents. If there are additional requirements and or other business workflows not met through the packaged implementation clients can add on additional scope as a follow on phase to the packaged deployment to create a more tailored fit solution. The additional requirements can be reviewed with Cority to provide an additional scope, effort and cost for additional phases of work.
Scaling
- Independence of resources
- We perform continuous monitoring of the system in terms of performance and capacity. We can detect when your system is running low on resources of capacity like database space or processing. We have the capacity to increase your resources when it is necessary.
Analytics
- Service usage metrics
- Yes
- Metrics types
- There are logs within the application that track when a user logs in and what records they view or update within the system.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data via the Cority ad hoc reporting tools.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Network boundaries between trusted and untrusted networks are protected with common state of the art protection methods to control the flow based on common standards (least privilege / need to have etc.) for in and outbound data flows. Security controls are implemented to identify threats and logfilesare collected and analyzed to identify anomalies according to the criticality.Firewall and router configurations restrict connections between untrusted networks and Customer's network, restrict inbound and outbound traffic to that which is necessary, and specifically deny all other traffic.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Please refer to the Cority SLA: https://www.cority.com/legal-center/service-level-agreement/
- Approach to resilience
- Cority maintains high availability services by maintaining redundant hardware-firewalls, servers and switches, multiple hosting locations, and dedicated failovers sites.
- Outage reporting
- If there are any service outages detected, a communication will be published on the Cority status page. Clients can subscribe to the page in order to receive any notices.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Security assignment is based modular configuration. The client will create a user profile and assign the user to a specific functional role. The role(s) will be granted access to specific modules within a Product Suite. Additional security features will allow the client to prohibit or grant explicit functions to a particular role and/or prohibit access to Reports, Fields, Metrics, Views, and the ability to Create Views. The security configuration can be assigned to a single user or multiple users who use the same profile.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type 2
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All Network components are managed and configured in an established service management framework (ITIL). Network Devices are hardened andaccess permissions are limited and restricted. Identification is happening viastrong authentication and changes are tracked and verified against masterconfiguration templates. The Cority internal Change Advisory Board oversees all physical and logical changes that may result in an interruption to service. Any maintenance, scheduled or otherwise, that potentially impacts clients will be communicated to the client base. Communication is sent at least seven days in advance with a reminder sent 24 hours in advance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Cority uses a third-party service to perform automatic vulnerability scans on its production services on a monthly basis. Issues of concern are prioritized and mitigated as soon as possible in accordance with the Cority Vulnerability Management Procedure. Cority performs external penetration and vulnerability tests regularly. BSI conducts annual network security audits in compliance with Cority's ISO27001 Certification for Information Security.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- As a SaaS provider, Cority monitors metrics from end-to-end in the aggregate for our hosting clients and can provide key data. Cority monitors transaction time, volume, bandwidth, download and upload speeds, and more. There sults are consolidated in an ApDex report which can be shared monthly.Over time, we will us this data help us optimize our solution to ensurewe are delivering maximum value to our clients.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Cority has formed team named Computer Security Incident Response Team. Upon a security breach, the CSIRT will: • Determine if an event constitutes a security incident. • Conduct an investigation to determine the root cause, source, nature, extent of damage • Preserve evidence of the incident • Interview affected personal • Act as a liaison with law enforcement and legal counsel • Manage the release of information to the media in co-ordination with corporate communications • Prepare reports of findings, root causes, lessons learned and actions for management review • Carry out the directions of management communicated through the CSO
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A short guided sandbox can be arranged for named individuals to test the pre-configured system for maximum two-week period, with regular check-ins with our solution team.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 15%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 24 November 2025
- What the ISO/IEC 27001 doesn’t cover
- Please refer to our certificate.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27017
- ISO 27018
- ISO 27001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
-