At CORTO, trust is at the core of everything we build.
Our Trust Centre is designed to provide clear, transparent information about the security, privacy, and reliability practices that underpin our platform. We know our customers rely on us to handle their data with the highest levels of care, and this responsibility shapes our technology, operations, and culture.
Trust Center Updates
We are pleased to share that CORTO's SOC 3 report, issued by independent auditor Sensiba LLP, is now available on our Trust Centre.
The SOC 3 report is a publicly available summary derived from our SOC 2 Type 2 attestation, based on the same Trust Services Criteria established by the American Institute of Certified Public Accountants (AICPA). While SOC 2 provides a detailed, confidential account of our controls for clients and partners under NDA, SOC 3 offers a general-use summary of the same audit results, allowing us to demonstrate our security posture transparently to a wider audience without requiring a non-disclosure agreement.
This report reflects CORTO's continued commitment to maintaining a mature, independently verified security program, and to being transparent with our clients about how we protect their data.
The SOC 3 report is available for download directly from our Trust Centre.
At CORTO, the security and confidentiality of our customers' data is of the utmost importance. We work year-round to maintain and continually improve our security posture, and we're pleased to share that CORTO has successfully completed its latest 12-month SOC 2 Type 2 audit period and been recertified.
SOC 2 Type 2 is a widely recognised framework for service organisations that evaluates not only the design of internal controls, but also their operating effectiveness over time. Our report was assessed against the Trust Services Criteria for Security, Availability and Confidentiality, confirming that the controls and processes protecting the data entrusted to us by our clients continue to operate effectively throughout the audit period.
This recertification reflects the ongoing commitment of our Information Security team, and of CORTO as a whole, to safeguarding our systems and our customers' information year after year.
Our latest SOC 2 Type 2 report is available to download from this Trust Centre. If you have any questions or would like more information about our security practices, please also visit our Knowledge Base.
We’re pleased to announce that CORTO has been successfully re-certified under the Data Privacy Framework (DPF) for the coming year, reaffirming our ongoing commitment to data protection and privacy.
This certification covers both:
- EU-U.S. Data Privacy Framework (EU-U.S. DPF)
- UK Extension to the EU-U.S. Data Privacy Framework
What this means for our clients:
- If your personal data transferred is from the EU and UK to the United States, it continues to be protected in accordance with recognised international privacy standards.
- CORTO remains aligned with regulatory expectations for lawful cross-border data transfers.
You can view our active certification on the official Data Privacy Framework website:
https://www.dataprivacyframework.gov/list
(Search for “CORTO”)
We’re pleased to announce that LawY is now powered by the CORTO platform. LawY utilises CORTO’s secure infrastructure and technology stack to deliver its services.
As a result, LawY integrates with CORTO’s established security boundary, leveraging the comprehensive controls, monitoring, and compliance.
Protecting the security, confidentiality, and reliability of our customers’ data remains central to everything we do at CORTO. As a trusted partner to legal professionals, we recognise the responsibility that comes with handling sensitive information and continuously strengthen our security posture.
We’re pleased to share that CORTO has been certified at CASA Tier 3 - the highest level within the Cloud Application Security Assessment (CASA) framework. CASA is an industry recognised framework built upon the OWASP Application Security Verification Standard (ASVS), providing a consistent, measurable approach to assessing application security. Achieving Tier 3 demonstrates that our platform implements rigorous security controls and adheres to the highest assurance level for application security compliance.
This recognition highlights the ongoing efforts of our Information Security team and reinforces CORTO’s commitment to maintaining the highest standards of protection and assurance for our clients.
To learn more about our approach to security and compliance, please visit our Security FAQs.
Subprocessors
- How is my personal/sensitive information stored?
- What measures do you take to protect my data?
- What personal/sensitive data do you collect?
- Do you comply with any cyber security frameworks?
- What should I do if I suspect a security issue with my account?



