Security & Trust

Built for trusted, governed AI at work.

CURA is a governed agentic workforce platform built on Microsoft Azure and integrated with Microsoft 365. Identity, authorization, tenant isolation, and human oversight are built into the architecture, not added afterward.

How CURA thinks about security

Six principles that shape every design decision across the platform.

  • Identity first

    Authentication and access decisions are anchored in Microsoft Entra ID.

  • Least privilege

    Microsoft Graph access is limited strictly to user-consented permissions.

  • Tenant-aware by design

    Platform data, memory, and requests are isolated to each customer's tenant boundary.

  • Human oversight

    Sensitive agent actions route into explicit human-in-the-loop review (HILR) gates.

  • Auditable operation

    User, agent, approval, and authorization activity is logged to support review.

  • Defense in depth

    Controls span identity, secrets, data, application, AI execution, and monitoring layers.

Where CURA stands today

Current status across the frameworks most relevant to CURA's customers, shown honestly, including work still underway.

  • GDPR

    CURA's architecture follows a GDPR-aligned design approach. DPAs and transfer safeguards can be established where required.

  • SOC 2

    SOC 2 compliance is actively being pursued as part of CURA's ongoing security roadmap.

  • EU AI Act

    Alignment with EU AI Act requirements is underway as part of CURA's compliance roadmap.

How CURA is built

Deterministic, sovereign cloud foundations engineering safe autonomy.

  • 01

    Identity & access

    CURA authenticates through your organization's existing Microsoft Entra ID environment. Role-based access and tenant-aware authorization keep every request scoped to the right user, role, and organization, with no separate CURA credential store required.

  • 02

    Data protection

    Platform data is encrypted in transit and at rest. Secrets are managed through Azure Key Vault, and tenant context is enforced across conversations, memory, agents, workflows, and audit records.

  • 03

    Infrastructure

    CURA runs on Microsoft Azure, using Azure-native services for identity, secrets, data, and monitoring, with automated backup, redundancy, and defined recovery targets built in.

  • 04

    AI governance

    Agents operate within authenticated tenant boundaries and approved tool access. Sensitive actions can require human approval, and approval decisions are recorded for accountability.

Request documentation

Security and procurement teams can request the following documents directly. Each request is reviewed before documentation is shared.

Technical Security Brief

Architecture, controls, threat model, data isolation & cryptographic audit trail details.

Need a deeper security review?

Request the CURA technical security brief, discuss your data-protection requirements, or bring your security team's questions directly to us.

Contact our team