Security
CC1–CC9
Protection against unauthorized access, both physical and logical.
- FIPS 140-3 encryption (AES-256-GCM)
- Per-project key derivation (HKDF-SHA256)
- Role-based access control
- MFA required for admin users
Trust & compliance
CogniSuite has completed an internal SOC 2 Type II self-assessment against the five Trust Services Criteria. We are preparing for a formal, independent audit. This page documents where we stand today.
At a glance
Note
This page documents an internal self-assessment, not an audited report. CogniSuite is not yet SOC 2 certified. A formal, independent SOC 2 Type II audit is planned for Q4 2026.
§01 · The standard
Overview
SOC 2 (System and Organization Controls 2) is an auditing framework from the AICPA that evaluates how an organization manages customer data across five Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy.
For a platform handling confidential deal data, SOC 2 is the shared language for describing those controls. A self-assessment is the internal first step: we map our controls to each criterion ourselves. An independent audit, planned for Q4 2026, is what turns that into a certified report.
§02 · Boundaries
Scope
The assessment covers the CogniSuite platform and the infrastructure it runs on.
§03 · Criteria
Coverage
SOC 2 evaluates an organization against five criteria. Below is how CogniSuite maps its controls to each one.
CC1–CC9
Protection against unauthorized access, both physical and logical.
A1
Systems are available for operation and use as committed.
C1
Information designated as confidential is protected as committed.
PI1
Processing is complete, valid, accurate, timely, and authorized.
P1–P8
Personal information is handled in line with our commitments.
§04 · Controls
Safeguards
§05 · Policies
Governance
The self-assessment is backed by written policies. Each is available as a Markdown document.
The full SOC 2 Type II self-assessment with control mappings.
Security requirements for systems, data, and operations.
Procedures for detecting and responding to security incidents.
Recovery procedures following disasters affecting systems.
Retention periods and deletion procedures for stored data.
Identified risks and the controls that mitigate them.
§06 · Timeline
Roadmap
The path from an internal self-assessment to an independent, certified report.
Feb 2026
Complete
Self-assessment against all five Trust Services Criteria completed and policy documentation written.
Q2 2026
In progress
Working through recommended action items, including backup restore testing and an external penetration test.
Q4 2026
Planned
Engage a third-party auditor for a formal SOC 2 Type II examination and report.
Ask our security team for documentation or to talk through your own compliance requirements.