Built for trusted, governed AI at work.
CURA is a governed agentic workforce platform built on Microsoft Azure and integrated with Microsoft 365. Identity, authorization, tenant isolation, and human oversight are built into the architecture, not added afterward.
How CURA thinks about security
Six principles that shape every design decision across the platform.
-
Identity first
Authentication and access decisions are anchored in Microsoft Entra ID.
-
Least privilege
Microsoft Graph access is limited strictly to user-consented permissions.
-
Tenant-aware by design
Platform data, memory, and requests are isolated to each customer's tenant boundary.
-
Human oversight
Sensitive agent actions route into explicit human-in-the-loop review (HILR) gates.
-
Auditable operation
User, agent, approval, and authorization activity is logged to support review.
-
Defense in depth
Controls span identity, secrets, data, application, AI execution, and monitoring layers.
Where CURA stands today
Current status across the frameworks most relevant to CURA's customers, shown honestly, including work still underway.
-
GDPR
CURA's architecture follows a GDPR-aligned design approach. DPAs and transfer safeguards can be established where required.
-
SOC 2
SOC 2 compliance is actively being pursued as part of CURA's ongoing security roadmap.
-
EU AI Act
Alignment with EU AI Act requirements is underway as part of CURA's compliance roadmap.
How CURA is built
Deterministic, sovereign cloud foundations engineering safe autonomy.
-
01
Identity & access
CURA authenticates through your organization's existing Microsoft Entra ID environment. Role-based access and tenant-aware authorization keep every request scoped to the right user, role, and organization, with no separate CURA credential store required.
-
02
Data protection
Platform data is encrypted in transit and at rest. Secrets are managed through Azure Key Vault, and tenant context is enforced across conversations, memory, agents, workflows, and audit records.
-
03
Infrastructure
CURA runs on Microsoft Azure, using Azure-native services for identity, secrets, data, and monitoring, with automated backup, redundancy, and defined recovery targets built in.
-
04
AI governance
Agents operate within authenticated tenant boundaries and approved tool access. Sensitive actions can require human approval, and approval decisions are recorded for accountability.
Request documentation
Security and procurement teams can request the following documents directly. Each request is reviewed before documentation is shared.
Technical Security Brief
Architecture, controls, threat model, data isolation & cryptographic audit trail details.
Need a deeper security review?
Request the CURA technical security brief, discuss your data-protection requirements, or bring your security team's questions directly to us.