CONNECT AI TRUST CENTER
AI-powered global trade begins with connection.Every trusted connection begins with security.
CONNECT AI operates the security, privacy and AI-governance controls needed to connect enterprise digital-trade data safely and transparently.
Secure. Trusted. Connected.
Trust status
ADA CASA verified
View verification scopeConsent-based data integration
Role-based access control
AI processing transparency
Built for enterprise
TRUST PRINCIPLES
Trust, designed before AI
Before we connect your data, we set the principles that protect it. CONNECT AI designs trust across four pillars.
Security
We apply access control, encryption, monitoring and security operations to protect enterprise data.
Privacy
We process data within the scope you consent to, and give you clear visibility and control over what is connected.
AI Governance
We define what AI does and does not do, and keep human review and control over important decisions.
Compliance
We continuously monitor changes in privacy, AI, cybersecurity and digital-trade regulation at home and abroad.
SECURITY ARCHITECTURE
Layered security
Security is not a single device but layers of controls working together. We describe it here at a concept level appropriate for public disclosure.
Identity & Access Management
We manage account authentication and access permissions, restricting access by role and privilege.
Data Encryption
We apply encryption in transit and at rest to protect data.
Application Security
We protect the application through input validation, secure coding practices and vulnerability checks.
Infrastructure Security
We protect the infrastructure layer through network segmentation and access control.
Logging & Monitoring
We record key activity and monitor for anomalies.
Incident Response
We maintain response procedures for security incidents and act as the situation requires.
Vendor Risk Management
We review the security risk of external services and partners.
Business Continuity
We operate backup and service-continuity practices.
We do not disclose specific system-configuration details that could be exploited. Detailed materials are provided separately through an enterprise security review request.
DATA PROTECTION
How is customer data protected?
From the moment of connection to the return of control, your consent and control travel with the data at every step.
- 01
User consent
We connect accounts and data only within the scope you allow.
- 02
Secure integration
We manage auth tokens and access permissions securely, and as a principle do not request more access than needed.
- 03
Minimal processing
We limit data processing to what the service requires.
- 04
AI analysis
AI analyzes data within a defined purpose and permission scope.
- 05
User review
You review the analysis and recommendations and make the final decision yourself.
- 06
User control
You can disconnect an integration, change permissions, and request deletion of data under policy.
EMAIL & WORKSPACE INTEGRATION
Email integration — how far do we process?
CONNECT AI and MORI connect only the scope you choose. There are two integration modes, and you decide which to use.
Mode 1
Behavioral signal analysis
We analyze sales-relevant behavioral signals such as whether an email was opened, clicked or replied to.
Mode 2
AI message mentoring
When you explicitly allow it, we analyze message content to suggest replies and follow-up sales direction.
Integration principles
- You choose.
- Only the scope you need is connected.
- You can change permissions at any time.
- AI suggestions go through your final review.
You can review and change the integration scope and processing in the privacy policy and your service settings.
RESPONSIBLE AI GOVERNANCE
Principles for trustworthy AI
AI is a tool that supports judgment; the decision-maker is you. CONNECT AI operates AI under the following principles.
Human Oversight
You give the final confirmation on important decisions.
Purpose Limitation
Collected data is processed within the purpose you consented to.
Data Minimization
We process only the minimum data needed to provide the service.
Transparency
We explain what AI does and the scope of data it uses.
Security by Design
Security and access control are considered from the design stage.
Continuous Monitoring
We continuously monitor changes in AI, privacy and cybersecurity regulation.
Frameworks and regulations we monitor
CONNECT AI monitors major global regulations and policy changes and continuously reviews their impact on our service and internal operating policies. The items below are reference frameworks and do not imply certification or full compliance.
GLOBAL COMPLIANCE MONITORING
Responding to global regulatory change
Digital trade sits where the regulations of many countries intersect. CONNECT AI continuously monitors regulatory change across key regions.
South Korea
Privacy
Rules on collection, use and provision of personal data and data-subject rights.
AI Framework Act
MonitoringAI
Domestic AI-related laws and policy developments.
Network Act
MonitoringCybersecurity
Stability and information protection for information & communications services.
European Union
- Monitoring
Privacy
EU General Data Protection Regulation.
EU AI Act
MonitoringAI
Risk-based regulatory framework for AI systems.
EU Cyber Resilience Act
MonitoringCybersecurity
Cybersecurity requirements for digital products.
United States
CCPA / CPRA
MonitoringPrivacy
California consumer privacy regulation.
NIST AI Risk Management Framework
MonitoringAI
Reference framework for AI risk management.
Japan
APPI
MonitoringPrivacy
Japan's Act on the Protection of Personal Information.
AI Business Guidelines
MonitoringAI
AI policy and guideline developments.
Singapore
PDPA
MonitoringPrivacy
Personal Data Protection Act.
Model AI Governance Framework
MonitoringAI
Reference framework for AI governance.
China
PIPL
MonitoringPrivacy
Personal Information Protection Law.
Data Security Law (DSL)
MonitoringCybersecurity
Rules on data processing and transfer.
The status shown reflects our monitoring/review of regulatory change and does not assert full compliance with any specific regulation.
CERTIFICATIONS & ASSURANCE
Certifications & assurance
We list only items whose certification or verification is confirmed. Planned items are shown separately as a roadmap and are never presented as obtained.
ADA CASA — Letter of Validation
VerifiedPassed App Defense Alliance (ADA) CASA (Cloud Application Security Assessment) Tier 2 and received a Letter of Validation from TAC Security. Through a Self-Assessment Questionnaire (SAQ) and Dynamic Application Security Testing (DAST), it validates the security of applications that use sensitive scopes such as Gmail.
- Issuer / verifier
- TAC Security · Google Preferred ADA CASA Assessor
Scope, issuer, issue date and validity are shown only per the official certificate, and are withheld until confirmed.
SERVICE STATUS
Service status
Operational status for CONNECT AI services.
A real-time status API is in preparation. The status shown is not a live value and is updated by the operations team. Incident and maintenance notices are delivered via separate announcements.
- CONNECT AI PlatformStatus page in preparation
- MORIStatus page in preparation
- JENAStatus page in preparation
- AuthenticationStatus page in preparation
- Email IntegrationStatus page in preparation
- AnalyticsStatus page in preparation
FAQ
Frequently asked questions
Answers to common questions about security, privacy and AI.
No. By default the analysis centers on behavioral signals such as opens, clicks and replies. Message-content analysis (e.g. reply suggestions) is performed only when you explicitly allow it.
Yes. You choose the integration scope and can change permissions or disconnect at any time.
No. AI provides drafts and suggestions; you review them and decide whether and what to send.
Yes. You can disconnect an integration in your settings; once disconnected, data processing through that integration stops.
Yes. You can request deletion through disconnecting an integration and account withdrawal. Specific retention and deletion criteria follow the privacy policy.
We passed App Defense Alliance (ADA) CASA (Cloud Application Security Assessment) Tier 2 and — through a Self-Assessment Questionnaire (SAQ) and Dynamic Application Security Testing (DAST) — received a Letter of Validation from TAC Security, a Google Preferred ADA CASA assessor. The exact assessed scope, issue date and validity follow the official Letter of Validation; please request detail through the security contact if needed.
Please report vulnerabilities and incidents through the security contact at the bottom of this page or the security email. We confirm and act promptly.
Yes. Enterprises and institutions evaluating adoption can request security, privacy and AI-governance materials through a security-review request.
Items to be answered once policy is confirmed
The items below require confirmation of exact policy, and we do not publish unverified answers. If you need detail, please request it through the security contact.
- Whether customer data is used for AI model training
- Data retention period
- Data storage country / location
- Subprocessor list
- Administrator access-permission detail
- Deletion processing time and backup-data deletion policy
ENTERPRISE SECURITY REVIEW
Need materials for an enterprise security review?
For enterprises and institutions evaluating CONNECT AI, we provide materials on security, privacy and AI governance.
Available materials
- Security OverviewOn request
- Privacy OverviewOn request
- AI Governance OverviewOn request
- Data Flow OverviewOn request
- Subprocessor ListOn request
- Business Continuity OverviewOn request
- Certification DocumentsOn request
- Vendor Security QuestionnaireOn request
SECURITY CONTACT
Questions about security and trust
Leave a trust-related inquiry — enterprise security review, data processing, AI governance, or a request for certification materials.
Found a security vulnerability?
Please report product or service vulnerabilities directly to the email below. We will confirm and act on it promptly.
Report a vulnerability by emailSecurity email
support@connectai.kr