Security is a shared responsibility. Kogniflow maintains technical and organizational controls proportionate to the Service and the risks associated with financial and business data. This page intentionally describes control objectives rather than sensitive implementation details. Specific contractual commitments are set out in the Data Processing Agreement and any applicable order form.
1. Security program and risk management
Security work is organized around risk assessment, defined responsibilities, preventive and detective controls, incident readiness, and periodic review. Controls are adjusted as the Service, threat landscape, legal obligations, and supplier environment change. Security information is shared on a need-to-know basis so transparency does not create avoidable attack paths.
2. Access management
- Service access requires authentication and is authorized by role and business need.
- Privileged access is restricted and separated from ordinary user access.
- Access rights are reviewed and removed when a role or engagement ends.
- Customer administrators control membership and permissions within their organizations.
3. Protection of data in transit and storage
Kogniflow uses safeguards designed to protect data while it is transmitted and stored. The control set includes secure transport, storage protections, managed secrets, environment separation, and authorization checks. The precise measures depend on the data flow and managed service involved and are reviewed against risk. We do not publish keys, internal network design, storage identifiers, or provider configuration.
4. Logging and monitoring
Security-relevant application and infrastructure events are logged and monitored to support availability, troubleshooting, misuse detection, and incident investigation. Access to logs is restricted, and retention is limited according to operational, security, and legal needs. We work to avoid placing unnecessary customer content in diagnostic records.
5. Secure development and change management
Changes to the Service follow controlled development and deployment practices. These include code review, automated checks, testing proportionate to the change, dependency management, separation of environments, and review of security-sensitive changes. Identified vulnerabilities are triaged and remediated according to risk.
6. Backup, continuity, and recovery
Kogniflow maintains backup and recovery arrangements appropriate to the Service and tests restoration or recovery processes on a risk-based basis. Service monitoring and operational procedures support detection and recovery from failures. Recovery objectives may be defined in a separate written service-level agreement where required.
7. Incident response
Security events are assessed through an incident process covering escalation, containment, investigation, evidence preservation, recovery, communication, and follow-up improvements. If an incident affects Customer Personal Data, Kogniflow notifies the affected Customer without undue delay after becoming aware of a personal data breach and provides available information needed for the Customer's own obligations.
8. Supplier security
Suppliers that may access or process customer data are assessed in proportion to their role and risk. Contracts include appropriate confidentiality, privacy, security, incident, and deletion obligations. Access and data sharing are limited to the supplier's function. See the Subprocessor register for current providers and relevant processing information.
9. Deletion and access offboarding
Kogniflow applies retention and deletion processes based on Customer instructions, contractual requirements, backup cycles, and applicable law. Access is revoked when no longer required. At the end of processing, Customer Personal Data is returned or deleted as described in the DPA, with legally required or protected backup copies isolated until their retention period ends.
10. Customer responsibilities
Customers contribute to security by:
- assigning access according to role and promptly removing inactive users;
- protecting credentials and using the authentication controls made available;
- connecting only authorized data sources and integrations;
- reviewing generated analysis before relying on it for material decisions;
- maintaining secure endpoint devices and source systems; and
- reporting suspected misuse or unauthorized access promptly.
11. Security contact
Report a suspected vulnerability or security incident to support@kogniflow.com. Please include enough information to reproduce or assess the issue, but do not send personal data, credentials, or exploit code by ordinary email. We will coordinate a secure channel if sensitive details are needed.