Security and Trust at Cognaium
Cognaium is committed to protecting your data with enterprise-grade security, transparent AI practices, and compliance with global privacy regulations.
SOC 2 Compliance
Encryption
At Rest: All data is encrypted at rest using AES-256 encryption via AWS Key Management Service (KMS). Encryption keys are rotated annually.
In Transit: All communications are encrypted using TLS 1.2 or higher. HSTS (HTTP Strict Transport Security) is enforced across all endpoints with a minimum max-age of one year.
Password Security: User passwords are hashed using bcrypt with a cost factor of 12 or higher. Passwords are never stored in plaintext or reversible form.
Access Control
Cognaium implements Role-Based Access Control (RBAC) with the following roles: Admin, HR, Manager, and Employee. Each role has strictly scoped permissions.
Multi-tenant data isolation ensures that no organization can access another organization's data. All access is scoped by tenant at the database query level.
Incident Response
Breach Notification: In the event of a data breach, affected parties will be notified within 72 hours of confirmation, in compliance with GDPR Article 33.
Incident Response Plan: We maintain a documented Incident Response procedure with SEV1-4 classification, escalation matrix, quarterly tabletop exercises, and post-incident review (PIR) process.
Penetration Testing: We conduct annual third-party penetration testing. Contact us for details on our testing programme and findings summary.
Security Contact
To report a vulnerability or security concern: [email protected]
See also: /.well-known/security.txt
ISO 27001 / ISO 27701
ISO 27001: Cognaium is implementing an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022. Certification is planned.
ISO 27701 (PIMS): Our privacy programme is aligned with ISO/IEC 27701 (Privacy Information Management System), including Records of Processing Activities (RoPA), Data Protection Impact Assessments (DPIAs), and structured data subject rights processes.
Data Retention: Retention periods are defined per data category. Application data: duration of hiring process + 2 years. Proctoring images: 30 days auto-deletion. Assessment results: retained per organization policy. See our Privacy Policy for full details.
Data Protection Officer
DPO Contact: [email protected]
Privacy Inquiries: [email protected]
Sub-processors: View our full Sub-processor List.
Your Data Rights (GDPR / CCPA / DPDP)
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right of Access — Request a copy of your personal data (request access)
- Right to Rectification — Request correction of inaccurate data (request correction)
- Right to Erasure — Request deletion of your personal data (request deletion)
- Right to Data Portability — Receive your data in a machine-readable format (request export)
- Right to Restrict Processing — Limit how we process your data
- Right to Object — Object to processing based on legitimate interests (submit objection)
Response Timeline: We respond to all data subject requests within 30 days (GDPR) or 45 days (CCPA/CPRA).
Cross-Border Transfers: Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework. See our Privacy Policy Section 7 for details.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know what personal information is collected and how it is used
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information
- Right to limit the use of sensitive personal information
Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. You will not receive different service quality, pricing, or access for making a privacy request.
India Data Protection (DPDP Act)
For users in India, Cognaium complies with the Digital Personal Data Protection Act, 2023 (DPDP Act):
- Rights: Access, correction, erasure, grievance redressal, and consent withdrawal
- Grievance Officer: Grievance Officer, Cognaium — [email protected] (subject: “DPDP Grievance”)
- Consent Withdrawal: Indian users can withdraw consent at any time by contacting the Grievance Officer. Note that withdrawal may affect your ability to use certain services.
NYC Local Law 144 (AEDT Compliance)
Cognaium's AI assessments qualify as Automated Employment Decision Tools (AEDT) under NYC Local Law 144. We comply with the law's requirements for bias auditing and candidate notification.
- Independent bias audits are conducted per the law's requirements
- Candidates are notified before any AI-evaluated assessment
- Candidates may request an alternative non-AI assessment method
EU AI Act Compliance
Our AI hiring tools are classified as HIGH-RISK under the EU AI Act (Regulation 2024/1689, Annex III, Section 4 — Employment and recruitment).
We provide full transparency documentation including system purpose, performance metrics, limitations, and human oversight mechanisms. No hiring decision is made solely by AI.
Compliance deadline: August 2, 2026. Cognaium is implementing compliance measures ahead of this date.
Assessment Fairness (EEOC/UGESP)
Our AI assessments are designed to minimize disparate impact across all protected groups. We apply the four-fifths (80%) rule and monitor selection rates by race, gender, age, and disability status.
We follow the Uniform Guidelines on Employee Selection Procedures (UGESP, 29 CFR Part 1607) as a framework for evaluating adverse impact.
Infrastructure
Hosting: AWS (Amazon Web Services), multi-availability-zone deployment for high availability.
Security Headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are enforced on all responses.
Monitoring: Continuous infrastructure monitoring with automated alerting for security events.
Questions?
For security inquiries, compliance questionnaires, or DPA requests: