Trust & compliance

SOC 2 compliance

CogniSuite has completed an internal SOC 2 Type II self-assessment against the five Trust Services Criteria. We are preparing for a formal, independent audit. This page documents where we stand today.

At a glance

Framework
SOC 2, Type II
Criteria
All five Trust Services Criteria
Current stage
Self-assessment complete (Feb 2026)
Independent audit
Planned Q4 2026

Note

This page documents an internal self-assessment, not an audited report. CogniSuite is not yet SOC 2 certified. A formal, independent SOC 2 Type II audit is planned for Q4 2026.

§01 · The standard

Overview

What is SOC 2?

SOC 2 (System and Organization Controls 2) is an auditing framework from the AICPA that evaluates how an organization manages customer data across five Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy.

For a platform handling confidential deal data, SOC 2 is the shared language for describing those controls. A self-assessment is the internal first step: we map our controls to each criterion ourselves. An independent audit, planned for Q4 2026, is what turns that into a certified report.

§02 · Boundaries

Scope

What is covered

The assessment covers the CogniSuite platform and the infrastructure it runs on.

Infrastructure
  • Production server (Zürich, Switzerland)
  • Go application binary
  • Encrypted SQLite database
  • Caddy reverse proxy
Data types
  • M&A deal documents
  • Financial data
  • Transaction details
  • Participant information
User types
  • Firm admins and members
  • Contributor organizations
  • Participant organizations
  • Observers

§03 · Criteria

Coverage

The five Trust Services Criteria

SOC 2 evaluates an organization against five criteria. Below is how CogniSuite maps its controls to each one.

Security

CC1–CC9

Protection against unauthorized access, both physical and logical.

  • FIPS 140-3 encryption (AES-256-GCM)
  • Per-project key derivation (HKDF-SHA256)
  • Role-based access control
  • MFA required for admin users

Availability

A1

Systems are available for operation and use as committed.

  • 99.9% uptime service commitment
  • 4-hour recovery time objective
  • Daily encrypted backups
  • Swiss data center (Zürich)

Confidentiality

C1

Information designated as confidential is protected as committed.

  • All deal data encrypted at rest
  • Blind indexes for searchable encryption
  • TLS 1.3 for all connections
  • Dynamic document watermarking

Processing Integrity

PI1

Processing is complete, valid, accurate, timely, and authorized.

  • Input validation on all data
  • Parameterized SQL queries
  • Optimistic locking (ETag)
  • ACID transaction compliance

Privacy

P1–P8

Personal information is handled in line with our commitments.

  • GDPR, FADP, and CCPA aligned
  • Data export on request
  • No third-party tracking
  • No data sales

§04 · Controls

Safeguards

Key security controls

Encryption
FIPS 140-3 validated AES-256-GCM, with per-project keys derived via HKDF-SHA256.
Authentication
JWT tokens with a 1-hour expiry, MFA required for admin users, and managed sessions.
Authorization
Role hierarchy (Admin → Contributor → Participant → Observer), invitation-only access.
Infrastructure
Swiss data center, UFW firewall, SSH key-only access, and automatic security updates.
Audit logging
Every access logged with actor, timestamp, and IP. Seven-year retention for compliance.
Backup and recovery
Daily encrypted backups, 4-hour RTO, 24-hour RPO, and tested recovery procedures.

§05 · Policies

Governance

Policy documents

The self-assessment is backed by written policies. Each is available as a Markdown document.

§06 · Timeline

Roadmap

Audit timeline

The path from an internal self-assessment to an independent, certified report.

  1. Feb 2026

    Complete

    Self-assessment

    Self-assessment against all five Trust Services Criteria completed and policy documentation written.

  2. Q2 2026

    In progress

    Gap remediation

    Working through recommended action items, including backup restore testing and an external penetration test.

  3. Q4 2026

    Planned

    Formal SOC 2 Type II audit

    Engage a third-party auditor for a formal SOC 2 Type II examination and report.

Questions about compliance?

Ask our security team for documentation or to talk through your own compliance requirements.