ZORTREX / FAQ

Frequently asked questions

Frequently asked questions

Clear answers about Zortrex, independent execution authority, and the evidence required to evaluate a proposed deployment.

Clear answers about Zortrex, independent execution authority, and the evidence required to evaluate a proposed deployment.

What is Zortrex developing?

Zortrex is developing an approach to independent execution authority: checking whether a proposed digital action has the required authority before it proceeds. Its public platform material describes a boundary between intelligent systems and consequential actions.

What does execution authority mean?

In this context, it means permission for a particular action, against a particular resource, under the conditions that apply at that moment. It should not be confused with the ability to perform an action or possession of a login.

How is this different from identifying an AI agent?

Identification addresses who or what is acting. The authority question is whether that actor is entitled to perform the specific action now. The design should make both questions explicit rather than letting one substitute for the other.

What is PresenceGate?

The public capability page describes a presence-related control for consequential actions. The refreshed documentation will need to explain its exact scope, supported environment and relationship to the separately presented mobile demonstration.

Does a demo prove production readiness?

No. A demonstration illustrates or exercises a declared scenario. Readiness requires evidence for the target environment, including integration, security, operational behaviour and failure handling. Ask for the version and evaluation scope behind any demonstration.

What happens when a condition is not satisfied?

The intended authority model distinguishes allowing an action from refusing it. The exact behaviour, reasons and recovery process must be confirmed for the specific implementation being evaluated.

Can existing identity or security controls be removed?

Do not assume that. A technical assessment should establish which controls remain necessary, how systems interact and whether any replacement is justified. The website should not imply that one authority component replaces an organisation’s wider security programme.

What data is collected or retained?

That depends on the component and deployment. Review a current data-flow and retention description covering requests, identity signals, logs, backups and third parties. A short marketing statement is not a substitute for that assessment.

Is Zortrex certified or independently assessed?

Only a current, attributable statement with the assessed scope should answer that question. The refreshed trust page should identify available evidence and distinguish internal testing from independent assessment; it must not invent a certification.

Does tokenisation replace all encryption?

Not as a general rule. Tokenisation and encryption address different design questions, and implementations vary. Any Zortrex-specific claim must define the protected data, token mechanism and remaining cryptographic dependencies.

Which deployment models and integrations are supported?

Confirm the currently supported versions and environments during technical evaluation. The website should publish an approved compatibility list rather than imply support for every cloud, device, operating system or enterprise application.

How do I begin an evaluation?

Use the approved enquiry route to describe the workflow, the action that needs control and the relevant environment. The next step should establish fit, scope, prerequisites and evidence requirements before any production commitment.

Zortrex, the constitutional platform

© 2026 Zortrex