Trust & Security

Data Security

How we protect your data and govern automated action across CogniFlow — from multi-tenant isolation and encryption to the emergency stop, the tamper-evident audit record, and the fully air-gapped Secure deployment.

Effective 13 June 2026 · Applies to Cognitive Lab and the CogniFlow platform
Template notice. This page describes Cognitive Lab's data-security approach for CogniFlow in customer-facing terms. Review it with counsel and your security lead before publishing, and confirm every claim reflects your live controls and any certifications you actually hold. Do not publish a certification (e.g. SOC 2, ISO 27001) until it is achieved; the page marks these as "on our roadmap" where not yet held.

1. Our security principles

Security is built into CogniFlow, not bolted on. Four principles guide every design decision:

2. Deployment models

ModelWhere it runsBest for
Standard & Industry 5.0 (cloud)Cognitive Lab's managed, multi-tenant cloudMost manufacturers
CogniFlow SecureEntirely inside the customer's own environment, air-gappedDefense, government, critical infrastructure

The same security principles apply across all models. The Secure model additionally keeps all data and processing within the customer boundary, with no external calls — see Section 9.

3. Multi-tenant isolation

In our cloud tiers, every customer workspace ("tenant") is logically isolated. Each request is bound to its tenant, and the platform is designed so that one tenant can never read, query, or infer another tenant's data. Tenant isolation is enforced consistently across the platform — including the dashboards and APIs that present data — and is verified by our automated test suite.

4. Access control & authentication

5. Encryption

Data is encrypted in transit using industry-standard TLS, and at rest using strong, widely adopted encryption. Secrets and credentials are managed through dedicated secret-management facilities rather than stored in code or configuration.

6. Safe automation by design

CogniFlow can recommend actions and, where you enable it, take bounded actions in your systems. This capability is wrapped in safety controls that are part of the product's design, not optional add-ons:

7. Audit & accountability

Consequential events — recommendations, approvals, automated actions, reversals, and administrative changes — are recorded in a tamper-evident audit record that can be reconstructed in plain language after the fact. Access to dashboards and data is itself auditable. This makes automated operations explainable, accountable, and defensible to auditors and regulators.

8. Protecting your data — and our IP

Our confidentiality model protects both directions:

9. CogniFlow Secure (air-gapped / defense)

10. Infrastructure & operational security

11. Vulnerability management

We keep dependencies current, monitor for known vulnerabilities, and apply security updates on a risk-prioritised basis. Our software is developed with security in mind, including code review and automated testing. We welcome responsible disclosure of potential vulnerabilities (see Section 14).

12. Incident response

We maintain an incident-response process to detect, contain, investigate and remediate security incidents. If a security incident affects your personal data or Customer Data, we will notify affected customers without undue delay and in line with applicable law and contractual commitments, and will cooperate on remediation.

13. Compliance & certifications

We design our practices to support our customers' obligations under applicable privacy and security laws, including Canada's PIPEDA, the EU/UK GDPR, and US state privacy laws. See our Privacy Policy for data-handling details and a Data Processing Addendum for GDPR customers.

Formal certifications such as SOC 2 Type II and ISO/IEC 27001 are on our roadmap as we scale. We will publish them here once achieved. (Remove this note and list certifications only when they are actually held.)

14. Reporting a security concern

If you believe you have found a security vulnerability or have a security concern, please contact us through the contact form and mark it as a security matter. We take every report seriously and will respond promptly. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.

Questions about this document? Contact our privacy and security team via the contact form. We respond personally within 48 hours.