For IT security officers, firm partners & procurement teams

Regulatory Compliance & Enterprise Trust

This page documents how Cortexeon Systems' products are designed to meet the regulatory and security requirements of regulated firms in Pakistan. Every standard named here is a design target: no product has yet been externally audited or certified against any of them. It is written to be used directly in vendor risk assessments; a copy-ready summary is provided at the end of this page.

Pillar 01

Human-in-the-Loop by Design

Cortexeon Systems' products function strictly as decision support systems: the software proposes; an authorized person decides. No AI output ever becomes a filed return, a signed working paper, or a sent client communication on its own.

  • Mandatory human review before anything is committed. No AI-generated draft, reconciliation, or disclosure note is saved as final, filed with a regulator, or sent to a client without explicit review and approval by a qualified person. These checkpoints are enforced by the workflow engine and cannot be disabled at the user level.
  • AI outputs are always labelled as AI outputs. Every AI-generated suggestion in the user interface is marked as such, with a confidence indicator and the underlying evidence shown alongside it — so a preparer, manager, or partner always knows what the model drafted and why.
  • Grounded answers, not fluent guessing. AI features are held to one rule: nothing is asserted that cannot be traced back to a record already in the engagement file. Where no record exists, the product says so instead of inventing an answer.

Pillar 02

Data Sovereignty: On-Premise, Zero Data Egress

Cortexeon products are deployed on-premise, entirely within your own infrastructure. In the standard deployment, client data is processed exclusively on your servers: Cortexeon Systems has no standing access to production data. For a profession bound by client confidentiality — a CA firm's engagement files above all — data sovereignty is an architectural property of the product, not a contractual afterthought.

  • On-premise processing and storage. All application hosting, data processing, and database storage occur on infrastructure you own and control — your office server, your data centre, or your private cloud tenancy. No client data is transmitted to, replicated to, or accessible from any Cortexeon-operated system. Fully air-gapped operation is supported.
  • Local AI inference by default. AI engines run against models hosted within your own perimeter — no outbound calls, no API key, and no third-party processor in your engagement letter. Client financial data never leaves the firm.
  • External model calls are opt-in only. Where a product offers an optional external frontier-model call for a specific capability, it is disabled by default and enabled only by an explicit administrator decision — never a requirement to run the core product.

Pillar 03

Audit Integrity: Tamper-Evident by Construction

Cortexeon products are built around the standards a Pakistani CA firm actually answers to — ISA 320 materiality, ISA 530 sampling, the ICAP QCR sign-off matrix, Companies Act 2017 disclosure requirements, and FBR / PRA / SRB / KPRA / BRA filing rules. These are design targets built into the product, not certifications: no external audit of the products has yet been performed.

  • Hash-chained, append-only audit trail. Every login, sign-off, materiality approval, sample draw, and AI-generated draft is written to a cryptographically chained log. Records cannot be silently altered or deleted; corrections are recorded as new entries with full lineage, and any tampering breaks the chain visibly.
  • Complete decision lineage. For any figure in the file, a reviewer — or a QCR inspector — can reconstruct the full chain: source record → AI-proposed draft and rationale → reviewer identity and changes → timestamped final approval. ISA 530 samples are reproducible exactly, months later.
  • Enforced separation of duties. A reviewer can never sign two consecutive levels of the same working paper, and system administrators can run the platform but structurally cannot sign audit or tax work.

Pillar 04

Enterprise-Grade Security & Access Control

Security controls are built into the products themselves — covering access control, encryption in transit and at rest, and secure development practices — rather than asserted in a data sheet. No external security certification has yet been obtained.

  • Strong authentication. TOTP multi-factor authentication, Active Directory / LDAP single sign-on for enterprise firms, automatic lockout after repeated failed logins, and forced password rotation after an administrator reset.
  • Role-based access control (RBAC) and data isolation. Granular roles separate AI-review, approval, administration, and audit functions. Tenant data is strictly isolated; least-privilege defaults apply to every role, and all administrative actions are themselves audit-logged.
  • Defense in depth. TLS 1.2+ for all data in transit, AES-256 encryption at rest, scoped short-lived service credentials, and segregated environments for development, staging, and production.

For your procurement file

Vendor Assessment Summary

The following summary is formatted for direct use in vendor risk assessments and security questionnaires. Use the button to copy it as plain text.

VENDOR ASSESSMENT · PLAIN TEXT
Vendor:                Cortexeon Systems Private Limited, Lahore, Pakistan
                       SECP Registration (CUIN): 0348123
Product(s):            AuditWP AI (audit working papers & QCR);
                       TaxPulse AI (tax compliance automation)
Contact:               contact@cortexeon-systems.com · +92 324-9986536

AI behaviour:          Decision support only. No AI output is filed, saved as
                       final, or sent to a client without review and approval
                       by a qualified person. AI outputs are labelled, with
                       confidence and underlying evidence displayed.

Deployment:            On-premise, on customer-owned and customer-controlled
                       infrastructure; air-gapped operation supported
Data residency:        Determined entirely by the customer; no client data is
                       transmitted to, or accessible from, Cortexeon systems
AI inference:          Models hosted within the customer perimeter by default —
                       no outbound calls. External model calls are opt-in only
                       and disabled by default.

Design targets:        ISA 320 / ISA 530, ICAP QCR sign-off matrix,
                       Companies Act 2017 disclosures, FBR / PRA / SRB /
                       KPRA / BRA filing rules. These are design targets:
                       no external audit or certification has been performed.
Audit trail:           Append-only, hash-chained log covering logins,
                       sign-offs, sample draws, and AI-generated drafts;
                       exportable for QCR inspection
Security:              TLS in transit, AES-256 encryption for secrets at
                       rest; TOTP MFA and AD/LDAP SSO; role-based access with
                       enforced separation of duties and per-engagement
                       staff assignment; row-level tenant isolation

For security questionnaires or any other detail a vendor assessment needs, contact contact@cortexeon-systems.com.