Trust & Security

How Cognocient handles your data

Cognocient is an early-stage company. This page states only what is actually built and verifiable today — not aspirational security marketing.

Data isolation

Every request to Cognocient's API is scoped to your authenticated account — every database query filters explicitly by your customer ID at the application layer.

Provider API keys

The OpenAI, Anthropic, and other provider keys you give Cognocient to proxy your calls are encrypted at rest (Fernet symmetric encryption) and only decrypted in memory for the moment needed to forward a request.

Proxy keys

Your Cognocient proxy key (the sk-cog-… key your app authenticates with) is stored as a bcrypt hash, never in plaintext. Revoking a key takes effect immediately.

Data in transit

All traffic to and from Cognocient is encrypted over HTTPS/TLS.

User accounts

Sign-in and session management run on Supabase Auth, a widely used third-party identity provider, rather than custom-built authentication code. On the Business plan, SAML 2.0 single sign-on (Okta, Microsoft Entra ID, Google Workspace, or any SAML identity provider) is available through the same provider, with domains that only route to your identity provider after you prove ownership with a DNS record, and an optional policy requiring SSO for every member. The account owner is deliberately exempt from that policy so a misconfigured identity provider cannot lock you out.

Role-based access control

Teammates get one of four roles (Admin, Developer, Finance, Viewer) beneath the account Owner, enforced on the server for every API call from a single policy table, not just hidden in the UI. Anything not explicitly classified defaults to admin-only, only the Owner can grant or remove the Admin role, and proxy keys cannot manage the team, billing, SSO, provider keys, or other keys.

Audit log

On the Business plan, every state-changing action and every denied attempt is recorded with who did it, their role, when, and from which IP, and can be searched and exported. Request bodies are never stored, so provider keys and identity-provider metadata cannot end up in the log. Entries are kept for 400 days and then deleted automatically; billing lifecycle events are kept seven years.

Provider keys in your own vault

On the Business plan, provider API keys can stay in your own AWS Secrets Manager, HashiCorp Vault or Azure Key Vault. Cognocient fetches a key at request time, holds it in memory for five minutes, and never stores or logs it. If the vault is unreachable the call fails clearly instead of using a stale key. Your vault credentials are encrypted at rest and cannot be read back.

Short-lived credentials and provisioning

On the Business plan, services can authenticate with short-lived JWTs from your own identity provider instead of long-lived API keys (asymmetric algorithms only; issuer, audience and expiry enforced), and SCIM 2.0 provisioning adds and removes team members automatically. SCIM can never grant the admin role, and a removed member cannot sign back in.

Customer-supplied endpoints

Custom model endpoints must be public HTTPS URLs. Because Cognocient calls them from its own servers, every URL is checked when you save it and again on each request: addresses that resolve to localhost, private networks, or cloud metadata services are rejected, and the connection is pinned to the address that was checked so DNS cannot be swapped underneath it.

What we see, and what we don’t

Cognocient is a proxy, not a read-only integration — by design, it sits in your request path so it can attribute cost and enforce budgets before a call happens. That means it does see your traffic in flight to forward it. What it does not do is store your prompt or response content by default: only metadata is logged — token counts, model, feature tag, cost, and latency. Full request/response tracing exists but is opt-in per call, via a request header you control.

If Cognocient is unreachable

Cognocient fails open. If the budget-check layer becomes unreachable, your calls pass through to your AI provider unaffected — you temporarily lose cost visibility and enforcement, but your application keeps working. A Cognocient outage is not designed to take down your production AI features. Read the full behavior.

If you suspect a compromise

Emergency Freeze is a one-click kill switch, on every plan including Free, that blocks all proxied calls immediately regardless of budgets — self-service to set and to clear. A proxy key suddenly called from a new source IP or model family raises a Compromise Risk signal, and Shadow Spend Reconciliation compares your provider's actual bill against what the proxy observed, to catch spend that bypassed Cognocient entirely. Read how it works.

What we don't have yet

No SOC 2 report, no bug bounty program, and no multi-region data residency offering yet — Cognocient runs on a single-region infrastructure today. We'd rather tell you that plainly than imply otherwise.

Found a security issue?

Please report it to security@cognocient.com.