Corda Security, Privacy & Compliance Center
Last Updated: September 1, 2026
At Corda AI (“Corda”), we build enterprise-grade intelligence tools designed to handle data with uncompromising security, privacy, and regulatory compliance. Corda’s parent company is Viacon FZCO.
As Corda expands its global footprint across the United States and the United Arab Emirates (UAE), our platform adheres to strict international regulatory frameworks, data sovereignty mandates, and industry-standard security safeguards.
Trust Overview: Corda guarantees it does not use customer data to train general-purpose AI models, implements end-to-end encryption in transit and at rest, and provides enterprise escrow protection options for uninterrupted operational continuity.
Table of Contents
1. Regulatory Compliance Framework
Corda operates under a robust global compliance program aligned with leading international privacy and data protection standards. Our architecture is designed to meet strict legal obligations across our primary launch markets in the US and the UAE, as well as in other global regions.
| Framework / Regulation | Jurisdiction | Key Compliance Safeguards |
| EU / UK GDPR | European Union & United Kingdom | Full alignment with Data Controller / Data Processor roles, execution of Standard Contractual Clauses (SCCs), Lawful Basis mapping, Data Protection Impact Assessments (DPIAs), and 72-hour breach notification protocols. |
| UAE PDPL (Federal Decree-Law No. 45/2021) | United Arab Emirates (Middle East) | Compliance with UAE Personal Data Protection Law, localized UAE cloud hosting options, strict cross-border transfer controls, and alignment with the UAE Data Office regulations. |
| US State & Federal Privacy Laws | United States (CCPA/CPRA, CPA, VCDPA, etc.) | Honors Consumer Privacy Rights (Right to Access, Delete, Correct), supports Global Privacy Control (GPC) opt-outs, and strictly prohibits selling or unauthorized sharing of customer data. |
| SOC 2 Type II & ISO 27001 Alignment | Global Standard | Operational procedures aligned with AICPA Trust Services Criteria (Security, Availability, Confidentiality) and ISO 27001 information security management principles. |
2. Comprehensive Data Privacy Practices
Privacy is embedded directly into Corda’s software architecture (Privacy by Design and Privacy by Default). We provide clear transparency regarding data usage, ownership, and user rights.
Data Ownership & Processing Roles
- Customer Workspace Data (Processor): You retain full ownership of all prompts, configuration settings, campaign files, and AI inputs. Corda acts strictly as a Data Processor or Service Provider operating under your written directions and our Data Processing Addendum (DPA).
- Account & Telemetry Data (Controller): For user authentication, workspace billing, diagnostic logs, and platform analytics, Corda acts as a Data Controller or Business.
Artificial Intelligence & Model Privacy
- No Training on Customer Data: Corda does NOT use Customer Data, AI inputs, or generated outputs to train, re-train, or fine-tune general-purpose public AI models.
- Vendor Commitments: All underlying AI infrastructure vendors (e.g., LLM providers) are bound by zero-data-retention or strict non-training contractual terms.
- Anonymized Telemetry: We use only fully de-identified and aggregated system performance statistics for engineering quality control.
Data Subject Rights & Regional Controls
Users in the US, UAE, and EEA/UK can exercise their privacy rights at any time, including:
- Right of Access & Portability: Request export of workspace data in standard machine-readable formats.
- Right to Erasure (Deletion): Request removal of account data and workspace assets (completed within 60 days in production and 90 days in backups).
- Right to Rectification: Modify incorrect contact, account, or preference records directly or via support.
- Opt-Out Preference Signals: Native browser-level detection for Global Privacy Control (GPC).
3. Technical & Operational Security Practices
Corda employs a multi-layered defense-in-depth security model to safeguard infrastructure, application data, and user access points.
Data Encryption & Cryptography
- Encryption in Transit: All web, API, and service traffic is encrypted using Transport Layer Security (TLS 1.3/1.2) with strong cipher suites.
- Encryption at Rest: Customer databases, configuration files, and backups are encrypted using AES-256 bit encryption standard.
- Key Management: Encryption keys are rotated regularly and managed via dedicated Hardware Security Modules (HSM) or cloud KMS infrastructure.
Infrastructure & Access Controls
| Security Domain | Technical Safeguards Implemented |
| Access Management | Multi-factor authentication (MFA) enforcement, Single Sign-On (SSO/SAML 2.0) integration, Role-Based Access Control (RBAC), and Least-Privilege access principles. |
| Network Defense | Virtual Private Clouds (VPC), automated DDoS protection, Web Application Firewalls (WAF), and automated intrusion detection. |
| Vulnerability Management | Automated code scanning (SAST/DAST), third-party dependency scanning, continuous patch management, and annual third-party penetration tests. |
| Incident Response | 24/7 security logging, automated threat alerting, dedicated incident response team, and formal breach notification protocols. |
4. Source Code & Data Escrow Protection
To provide maximum risk mitigation and operational guarantee for enterprise clients, particularly large organizations in the US and UAE, Corda offers formal **Escrow Protection** agreements.
Enterprise Software & Data Escrow Options
Through our partnership with leading global escrow agents, enterprise accounts can secure software continuity guarantees:
- Source Code Deposit: Corda’s core source code, deployment scripts, and architectural configurations are periodically deposited into secure third-party escrow vaults.
- Database & Asset Protection: Automated snapshots of customer schema structures and encryption keys are securely held under escrow terms.
- Specified Release Conditions: In the unlikely event of insolvency, bankruptcy, or failure to maintain core services as defined in our enterprise agreement, designated release conditions grant customers access to essential assets to ensure zero disruption to their business operations.
5. Data Residency & Cross-Border Transfers
To support localized privacy mandates in the UAE and regional requirements in North America, Corda provides flexible data hosting choices.
| Region | Deployment Availability | Compliance & Residency Details |
| United States (US) | Primary / Default Region | Hosted on top-tier US cloud data centers (SOC 2, ISO 27001 certified). Meets US state data privacy requirements. |
| United Arab Emirates (UAE) | Launch Available | In-region UAE cloud infrastructure ensuring local data residency and compliance with UAE PDPL cross-border rules. |
| Custom Regional Isolation | Enterprise Plans | Dedicated tenant isolation and customer-managed encryption key (CMEK) options. |
6. Contact Security & Compliance
If you have questions regarding our compliance framework, security practices, Data Processing Addendum (DPA), or escrow agreements, please contact our security team. Reach out @hello.corda.co
Contact Security & Compliance
For security or compliance inquiries, please contact our team at compliance@corda.com