Mission
Defend the machine without reading the person.
Security should not be something you buy by handing over your privacy. Corxor is built so that an organisation can be defended without its people being watched, and so that a customer keeps the thing every other vendor asks them to give up: independence over their own data.
-
Behaviour is the evidence. Content never is.
Arkor decides on what a program does, not on what a person wrote. A detection travels as exactly what a verdict needs: a SHA-256 fingerprint, the process, its parent and the account it ran as, the command line, the MITRE technique it maps to, the decision and the confidence behind it — plus the machine's name, OS and agent version so the fleet can be managed at all.
-
The fingerprint leaves. The file stays.
When Arkor needs something identified, it sends the hash, not the bytes. Even a false-positive report — the one place a customer is actively asking us to look at a file — carries the fingerprint and the file name, and nothing of the contents.
-
One exception, and we name it.
A Critical incident produces a forensic snapshot scoped to that incident, so the investigation it opened can actually be carried out. It is size-capped, stored inside your own tenant, and deleted on a schedule you control — thirty days unless you say otherwise. Each one is hashed on arrival and sealed into an append-only chain, and the certificate that comes with it can be verified by your lawyers or a forensic authority without any access to us. A vendor who claims nothing ever leaves the endpoint is either not doing forensics or not telling you what they do.
-
The list, for cloud tenants, in full
Your tenant holds the items above and nothing else. It never holds a document, a spreadsheet, source code, an email, a chat message, a browsing history, a keystroke, a screenshot, a clipboard, a microphone or camera capture, a stored credential, or the contents of any file. Two of the fields we do hold — the command line and the account a process ran as — can contain a person's name, which is why we describe what we take rather than claiming to take nothing personal. On-premise deployments keep all of it on your own infrastructure; there is no tenant on our side to hold anything.
-
A property of the protocol, not a promise.
None of this rests on good intentions. It is what the agent is able to send, it is visible in the console, and it is the kind of commitment that can be written into a contract and checked by an auditor rather than believed.