Kortex
snapshot · 2026-09-06

Trust & procurement

What your security and procurement review needs to know about Kortex, stated plainly; including what we do not yet have. Kortex is a product of Orkora Limited, sold through pilot programmes. We would rather state that clearly than imply enterprise scaffolding that does not exist yet.

Security posture

No opaque model decides a verdict

No generative or learned model controls a Kortex verdict. The answer path is deterministic: database reads, spatial joins and disclosed arithmetic, versioned at /methodology, where the rules that decide a verdict are published in full and served machine-readably at /v2/methodology. There is no LLM in the answer path, no machine-learned scoring and no analyst narrative. Where the evidence does not support a verdict, the screen abstains rather than estimates, and every answer carries a receipt pinned to graph and data snapshot identifiers; since methodology 1.29 that receipt also freezes the complete rulebook it was decided under, with a SHA-256 over it, so an answer can be audited against the rules in force when it was computed rather than the rules in force today.

This page used to say "there is no model to validate", and that was too strong. Kortex does contain models in the ordinary sense: the methodology describes weighted siting scores, a DC power-flow (PTDF) formulation, and modelled revenue and carbon layers. What is true, and what matters for model risk, is narrower and more defensible: those models are deterministic, their formulations and weights are published, they produce figures rather than verdicts, and none of them is a learned or opaque function. Deterministic is not model-free, and we should not have implied otherwise.

For buyers subject to model-risk frameworks (SR 11-7 and its UK/EU equivalents), the practical position is that every derivation is inspectable: sources, transformations, formulations, weights and methodology versions are all published, and every served figure states its basis. Your model-risk function can assess the classification from the public methodology record rather than taking a claim from us; we will answer their questions directly.

Where we do use a language model, and where we never do. One internal operations job uses a third-party language model to sift published public-sector procurement notices for our own bidding. It sits nowhere near the product: it reads public tender text, it writes to no customer-facing table, and nothing it produces reaches an answer or a receipt. No customer data, no query, no receipt and no candidate site is ever sent to a third-party model. If that changes we will say so here before it ships, not after.

Data protection

Your candidate data & receipts

Availability, backups & support

What we do not have yet; stated plainly. No formal SLA (a measured-uptime SLA comes with the first annual contracts). No SOC 2 or ISO 27001 certification (on the roadmap as the customer base matures; the controls above are what exists today, and we will not imply otherwise). No Cyber Essentials certification yet; for UK public contracts we work to the in-place-before-award position that PPN 09/23 allows. No 24/7 on-call rota. If your procurement gate requires these today, we are happy to discuss timelines honestly.

Commercial terms

Corporate compliance & insurance

Verify us

Company & continuity

Kortex is built by Orkora, a funded floating-nuclear developer, to screen sites for its own gigawatt-scale plants; the same evidence layer is what we sell.

Orkora Limited, registered in England and Wales (company no. 16555987), is a wholly-owned subsidiary of Orkora Inc. (United States), which has raised over $10m in institutional investment. Orkora Limited has no subsidiaries of its own. The team is 10 to 20 people and growing. kortex@orkora.com. Security questions, procurement questionnaires and vulnerability reports all go to the same address; questionnaires are answered directly by the people who operate the system.

Continuity commitments. Everything you buy is exportable in open formats (CSV, GeoJSON, JSON) throughout the contract. Answer receipts are self-contained documents: they remain readable and auditable after contract end, independent of platform access. On termination we provide a final export of your investigations and receipts before deletion on the agreed schedule.