Security and Compliance

Cognaize keeps your financial data safe with enterprise-grade security and data privacy controls.

The controls

How your data is protected

Your environment, your control

Run Cognaize in your own cloud or on-premise environment. Documents never leave your infrastructure.

Your data stays yours

Never used to train models for other customers. Improvements from your data stay in your deployment.

Encrypted everywhere

In transit and at rest, with customer-managed keys supported.

Least-privilege access

Role-based access control, with audit logs of who did what, and when.

Independently tested

Regular penetration testing and vulnerability scanning.

Built to recover

Redundancy, backups, and failover when hosted. DR templates and guidance when self-hosted.

Compliance

Independently audited

Cognaize maintains SOC 2 Type II compliance, examined by Insight Assurance against the AICPA trust services criteria.

AICPA SOC 2 — SOC for Service Organizations seal SOC 2 Type II Independently examined for security, availability, and confidentiality. Report available on request.
Penetration testing Performed regularly, with vulnerability scanning. Results available on request.
GDPR Designed to support GDPR compliance, with data-deletion and privacy controls.

Self-hosted deployments run entirely inside your infrastructure and inherit your institution's compliance posture.

The architecture

Auditable by design

Most security reviews stop at process. Cognaize's architecture adds something stronger: every output is verified against explicit rules, and every check is on record.

Deterministic outputs

Same document, same rules, same result, every run.

Every check traceable

Each value carries the checks it passed, so reviewers can see why a number is what it is.

Humans on the edge cases

Unresolved failures go to expert review instead of into your systems.

How verification works →
Security FAQ

Ask questions

The questions security and compliance teams ask us most.

What deployment options does Cognaize offer?

Cognaize offers two approaches: self-hosted (the software runs entirely in your cloud or on-premise environment, and your data never leaves it) and Cognaize-hosted (Cognaize runs the platform, with your choice of data region).

Can Cognaize access our data?

For self-hosted deployments, all data stays within your infrastructure and Cognaize does not access it during normal operations. For Cognaize-hosted deployments, access is strictly controlled, granted only with explicit customer authorization for specific support purposes, and fully logged.

How does Cognaize handle encryption?

Data is encrypted both in transit and at rest using enterprise-grade standards. For self-hosted deployments you control the encryption keys through your cloud provider; for Cognaize-hosted deployments, keys are managed in secure key vaults. Customer-managed keys are supported.

Is our data used to train models for other customers?

No. Customer data is not used to train models for other customers. Fine-tuning and improvements made with your data are your intellectual property and remain isolated to your deployment. General model improvements use Cognaize's proprietary data, not customer data.

What security assessments and testing has Cognaize completed?

Cognaize undergoes regular security assessments, including penetration testing and vulnerability scanning, and all code is available for you to scan with your own security tools.

What disaster recovery and redundancy does Cognaize provide?

For self-hosted deployments, you control the disaster-recovery strategy within your environment, with Cognaize providing DR templates and guidance. For Cognaize-hosted deployments, Cognaize maintains redundancy, backups, and failover procedures.

What access controls and audit logging does Cognaize provide?

Cognaize supports role-based access control on a least-privilege basis and maintains detailed audit logs of logins, data access, and changes (who, what, when).

Bring your security team.

Request a demo and we'll walk through deployment, data handling, and the SOC 2 report with your reviewers.

Request a demo