Cogny · Trust Center

Cogny Trust Center

Trust center

Cogny maintains a public trust center covering its security and compliance posture.

CompanyAi Enterprise SoftwareMarketingMarketing AnalyticsMarketing AutomationMCPAgentsData WarehouseAdvertising
Trust center: https://cogny.com/security

Certifications & Compliance

Source

Trust Center

Raw ↑
generated: '2026-08-13'
method: searched
source: https://cogny.com/security
url: https://cogny.com/security
checked: '2026-08-13'
name: Cogny Security
type: security-page
note: >-
  Cogny publishes a single self-hosted security page rather than a third-party
  trust portal (no Vanta/Drata/SafeBase surface, no trust.cogny.com — probed,
  404). The page is substantive: encryption posture, auth model, tenant
  isolation, GDPR handling, infrastructure, a named sub-processor register, and
  monitoring/incident response.
attestation_correction: >-
  IMPORTANT — a keyword probe of this page matches "SOC 2" and "ISO 27001", but
  BOTH strings occur only inside the DeepInfra, Inc. row of the sub-processor
  register ("Zero data-retention policy; SOC 2 and ISO 27001 certified"). They
  describe a SUB-PROCESSOR, not Cogny AB. Cogny publishes no SOC 2 report, no
  ISO 27001 certificate, and no PCI/HIPAA/FedRAMP claim anywhere on its public
  surface. Recording those certifications against Cogny would be a false
  attribution, so they are held below under third_party_certifications only.
certifications: []
certifications_note: >-
  None self-attested by Cogny AB as of the checked date.
compliance_programs:
- id: gdpr
  name: GDPR
  status: claimed
  self_attested: true
  evidence: >-
    Dedicated "GDPR Compliance" section — mandatory GDPR webhook endpoints
    implemented for third-party integrations that require them (Shopify customer
    data request, customer data erasure, shop data erasure); OAuth credentials
    auto-deleted from the vault on integration disconnect; user-requested account
    and warehouse deletion follow a scheduled confirm-then-purge process.
  source: https://cogny.com/security
- id: dpa
  name: Data Processing Agreement
  status: published
  url: https://cogny.com/terms/dpa
  http_status: 200
  evidence: >-
    Sub-processor contractual terms are set out in a published DPA linked from
    the security page.
- id: dora
  name: DORA addendum
  status: published
  url: https://cogny.com/terms/dora
  http_status: 200
  evidence: >-
    A DORA (EU Digital Operational Resilience Act) addendum is published in the
    terms set — relevant to EU financial-sector customers.
- id: eu-data-residency
  name: EU data residency
  status: claimed
  self_attested: true
  evidence: >-
    Compute on GKE europe-west1 (Belgium); Supabase managed Postgres on AWS
    eu-north-1 (Stockholm); Berget AI for EU-hosted inference. The single stated
    exception is Cogny Sites, which runs on Cloud Run in the customer's own GCP
    project and region — EU, North American and Asian regions available, fixed at
    creation.
  source: https://cogny.com/security
- id: ai-training-posture
  name: AI training posture
  status: claimed
  self_attested: true
  evidence: >-
    Both Anthropic and OpenAI rows of the sub-processor register state the
    provider "does not train on customer content submitted via the API"; Hugging
    Face "does not store request bodies or responses when routing"; DeepInfra
    "zero data-retention policy".
  source: https://cogny.com/security
security_controls:
  encryption_in_transit: TLS (HTTPS) for all data, including service-to-service
  encryption_at_rest: Supabase-encrypted database; OAuth tokens in Supabase Vault
  authentication: Supabase Auth (email/password + social login)
  third_party_oauth: OAuth 2.0 with HMAC signature verification on callbacks and webhooks
  tenant_isolation: >-
    Postgres Row-Level Security on all tables, scoped to the authenticated user's
    warehouse; stated that cross-tenant access is not possible at the DB layer.
  secret_handling: >-
    Access and refresh tokens stored in Supabase Vault; stated never written to
    application logs, client-side storage, or source code.
  ddos_waf: Cloudflare edge CDN, WAF and DDoS mitigation in front of all public endpoints
  ci_cd: Google Cloud Build with container image scanning
  monitoring: >-
    Real-time monitoring of application errors, tool-execution failures and
    security-relevant events, alerting engineering via Slack.
documents:
- name: Cogny Security Brief (PDF)
  description: >-
    A single vendor-review overview — company identity, data handling, storage
    and retention, sub-processors, AI-training posture, and MCP connector
    security. Offered as a download on the security page.
  url: null
  note: >-
    No stable public PDF URL is exposed in the page markup (probed
    /security-brief.pdf -> 404); the download appears to be generated or gated
    behind the page. Recorded as published-but-not-directly-addressable.
sub_processors:
  register_published: true
  source: https://cogny.com/security
  count: 13
  entries:
  - name: Google Cloud (Google LLC / Google Cloud EMEA Ltd.)
    purpose: Compute (GKE), BigQuery, object storage, build and deploy, Google-integration OAuth
    location: europe-west1 (Belgium); hosted sites in customer-selected region
  - name: Supabase, Inc.
    purpose: Managed PostgreSQL, authentication, encrypted secret vault, point-in-time recovery
    location: AWS eu-north-1 (Stockholm)
  - name: Cloudflare, Inc.
    purpose: Edge CDN, WAF, DDoS mitigation, TLS termination
    location: Global edge
    note: No personal data persisted at the edge
  - name: Anthropic PBC
    purpose: LLM inference (Claude) for AI reports and chat
    location: Global routing
  - name: OpenAI, L.L.C.
    purpose: LLM inference (GPT models) for AI reports and chat
    location: US + SCCs
  - name: Berget AI
    purpose: EU-hosted AI model inference
    location: EU (Sweden)
  - name: Hugging Face, Inc.
    purpose: Inference routing for open-weights LLMs
    location: US + SCCs
  - name: DeepInfra, Inc.
    purpose: LLM inference (DeepSeek open-weights) via Hugging Face routing
    location: US + SCCs
    third_party_certifications:
    - SOC 2
    - ISO 27001
    note: >-
      These certifications belong to DeepInfra, the sub-processor — NOT to Cogny.
      See attestation_correction above.
  - name: Brave Software, Inc. (Brave Search)
    purpose: Web search, news, and rank-check data for AI research tools
    location: US + SCCs
  - name: Stripe Payments Europe, Ltd.
    purpose: Subscription billing and payment processing
    location: EU + SCCs
  - name: Resend, Inc.
    purpose: Transactional email (report and auth emails)
    location: SCCs
  - name: Slack Technologies, LLC
    purpose: Internal alerting and optional customer notifications
    location: SCCs
  - name: ElevenLabs Inc.
    purpose: Optional text-to-speech, invoked only when audio features are used
    location: SCCs
legal_entity:
  name: Cogny AB
  address: Peter Myndes Backe 16, 118 46 Stockholm, Sweden
  jurisdiction: SE
related:
- https://cogny.com/privacy
- https://cogny.com/terms
- https://cogny.com/terms/dpa
- https://cogny.com/terms/dora
- https://cogny.com/cookies
last_updated_by_provider: 'March, 2026'