Cortex Cortex
Regulatory Intelligence API

Compliance intelligence
your platform can trust.

One API call. Dozens of regulatory frameworks. Citation-backed answers with a cryptographic audit trail. The regulatory reasoning layer for GRC platforms, consultancies, and enterprise.

cortex-api
73K+
Cited obligations
Ed25519
Signed audit receipts
API
Cloud, on-prem, or hybrid
Quarterly
Regulatory updates
Architecture

Three components. One API.

Cortex combines a purpose-trained model, a structured regulatory knowledge base, and an intelligence layer that verifies every answer before it leaves the system.

Cortex Model

Purpose-trained reasoning

Fine-tuned on thousands of supervised examples covering obligation extraction, cross-framework mapping, maturity assessment, and insufficiency detection. Trained specifically for regulatory reasoning, not general chat.

Apache 2.0 licensed / On-prem deployable / GGUF quantized
Cortex Knowledge

Structured regulatory corpus

Tens of thousands of normalized records spanning major US, EU, and international frameworks. Every obligation is typed, cited, and cross-linked. Real-time retrieval ensures answers reference actual regulatory text, not memorized approximations.

Updated quarterly / Cross-framework relationships / Citation-level provenance
Cortex Intelligence

Verified, auditable output

Every response is verified against evidence before delivery. Unsupported claims are flagged, not hidden. Every answer includes a cryptographically signed governance receipt your auditors can independently verify.

Ed25519 signed / Merkle-batched / Blockchain anchor-ready
Coverage

Broad regulatory coverage. Growing quarterly.

From US federal regulations to EU governance directives. Cortex works with the actual regulatory text, not summaries. Coverage includes the SureStep AI Governance Framework for AI-specific risk and control management.

NIST 800-171v3
NIST CSF 2.0
NIST AI RMF
CMMC 2.0
PCI DSS v4.0.1
HIPAA
SOC 2
GDPR
EU AI Act
DORA
NIS2
CIS Controls v8.1
CPS 234
UK Cyber Essentials
Essential Eight
EU-US DPF
12 CFR (Banking)
17 CFR (SEC)
16 CFR (FTC)
SureStep AI Gov

Partial list. All frameworks shown are publicly available regulatory texts. Additional frameworks and proprietary mappings available upon request.

Use cases

Built for the people who do compliance work.

GRC Platforms

Embed regulatory intelligence

Add compliance reasoning to your existing GRC platform via API. Your users ask questions in natural language, Cortex returns cited, verified answers. White-label ready.

Consultancies

Accelerate compliance engagements

Cross-framework mapping in seconds, not weeks. Ask Cortex how your client's PCI DSS controls map to NIST CSF, and get a cited answer with specific section references.

Enterprise GRC Teams

Deploy in your cloud or on-prem

For regulated industries that can't send data to third-party APIs. Cortex deploys inside your GCP, AWS, or Azure tenancy, or runs entirely on-premises with no cloud dependency.

Developers

Build compliance into your product

Standard REST API with OpenAPI spec. Extract obligations, query compliance, map frameworks, assess maturity. Every response includes a confidence score and governance receipt.

Endpoints

Five capabilities. One API key.

POST
/query
Ask any compliance question. Returns a cited, evidence-backed answer with confidence score.
POST
/extract-obligations
Extract structured obligations from regulatory text. Classifies mandatory, recommended, informational.
POST
/generate-controls
Generate control recommendations mapped to specific regulatory requirements.
GET
/governance/verify
Verify any previous response. Recompute fingerprint, validate Ed25519 signature, check Merkle proof.
GET
/admin/usage
Usage metering by tenant, endpoint, and time range. Built for billing integration.
Industries

Built for regulated industries.

Compliance AI only works if it understands the regulatory frameworks your auditors actually cite. Cortex is built with coverage-first thinking — real text, not summaries.

Financial Services

Banking, capital markets, insurance

PCI DSS, DORA, GDPR, Basel, FFIEC, OCC, 12 CFR, AML/CFT. Ask Cortex how a DORA ICT incident obligation maps to your existing NIST controls — and get a cited answer your auditors can verify.

  • Gap analysis across PCI DSS, DORA, and FFIEC simultaneously
  • Regulatory change impact assessment for new EU rules
  • Auditable AI responses for exam-ready documentation
Healthcare

Providers, payers, health tech

HIPAA, NIST 800-171, SOC 2, and state privacy laws. Embed Cortex into your GRC platform to automate HIPAA compliance Q&A with citations that point to actual regulatory text — not AI hallucinations.

  • HIPAA obligation extraction from policy documents
  • Cross-mapping HIPAA Security Rule to NIST CSF controls
  • On-premises deployment — PHI never leaves your environment
Defence & Government

Defence contractors, federal agencies

CMMC 2.0, NIST 800-171v3, NIST AI RMF, FedRAMP, and CIS Controls. Cortex speaks CMMC natively — designed for organizations navigating DoD supplier compliance requirements.

  • CMMC Level 2 & 3 readiness assessment via API
  • NIST 800-171 control gap identification with citations
  • Air-gapped deployment on classified or restricted networks
Deployment

Your cloud. Your data center. Your rules.

Cloud API

Build and integrate, fast

Get an API key and start building. Cortex is hosted on GCP with enterprise-grade infrastructure.

Enterprise SLA / Multi-region
Dedicated Cloud

Your cloud, our brain

Deploy Cortex inside your own GCP, AWS, or Azure project. Your VPC, your IAM, your audit logs. We never touch your data.

Terraform module / Single-tenant / GDPR-ready
On-Premises

Fully air-gapped

Docker package with GGUF model, regulatory corpus, and Cortex runtime. No cloud dependency. Runs on a single GPU server.

Docker Compose / Annual license / Zero telemetry
Plans

What's included in each deployment.

Contact us for pricing. All deployments include the full Cortex platform — your deployment model determines your infrastructure requirements.

Cloud API

API Access

For teams integrating regulatory intelligence into existing tools and workflows.

  • All five API endpoints
  • 20+ regulatory frameworks
  • Governance receipts included
  • Usage dashboard
Contact us for pricing →
Dedicated Cloud
RECOMMENDED

Platform & Enterprise

For GRC platforms and enterprises that need Cortex in their own cloud environment. Single-tenant, your VPC, enterprise SLA.

  • Everything in Cloud API
  • GCP / AWS / Azure deployment
  • Terraform module included
  • White-label ready
  • GDPR data residency
Contact us for pricing →
On-Premises

Air-Gapped

For defence, intelligence, and regulated industries where data cannot leave the building. Docker package, annual license, zero telemetry.

  • Everything in Dedicated Cloud
  • GGUF model included
  • No internet dependency
  • Runs on single GPU server
  • Zero telemetry, full audit
Contact us for pricing →
Get started

Ready to add regulatory intelligence?

Request early API access or schedule a technical walkthrough. We'll show you Cortex answering real compliance questions against your frameworks in under 10 minutes.

cortex@onyxailabs.com  ·  Response within one business day