Skip to content

Security, Privacy and Compliance at Cognician

Cognician is a secure, cloud-native SaaS platform with a mature ISO/IEC 27001-certified ISMS. Security and privacy are embedded into every layer of our platform– not added as an afterthought.


   Strong encryption & strict access controls

   Continuous monitoring & incident response

   Secure development aligned to OWASP


   GDPR compliant – DPF & SCCs in place

   Customer data never used to train AI models

   Annual independent pen testing & audits

Certifications Data Protection Access & Identity Cyber & Threat Detection AI & Responsible Use Architecture Independent Assurance Contact Security

 

Certifications and Compliance

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

1-May-20-2026-03-08-17-4403-PM

ISO/IEC 27001:2022

Certified Information Security Management System (ISMS), externally audited annually by an accredited certification body. Covers the full Cognincian platform and supporting operations.

Certified

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

2-May-20-2026-03-08-17-4221-PM

GDPR Compliance

Full compliance with the EU General Data Protection Regulation. The Cognician platform supports data subject rights including, access, erasure, and portability.

Compliant

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

3-May-20-2026-03-08-17-4176-PM

EU-US Data Privacy Framework (DPF)

Cognician supports international data transfers from the EU to the US under the EU-US Data Privacy Framework, established in 2023 as the successor to Privacy Shield following the Schrems II ruling. This ensures lawful transfer of personal data in accordance with EU adequacy requirements.

In place

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

4-3

Standard Contractual Clauses (SCCs)

Where the DPF does not apply, Cognician relies on the European Commission's Standard Contractual Clauses as a lawful mechanism for transferring data outside the EEA.

In place

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

5-1

NIST Cybersecurity Framework

Our security programme is risk-based and aligned with both ISO and NIST frameworks, covering Identify, Protect, Detect, Respond, and Recover functions with continuous monitoring and improvement cycles.

Aligned

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

ai_icon

EU Artificial Intelligence Act (EU AI Act)

Cognician has proactively aligned its AI governance framework with the principles of the EU AI Act, not simply because it may apply to us, but because we believe it represents the right foundation for responsible AI. The Act's risk-based methodology reinforces the same values that underpin our broader approach to security and privacy: that trust must be earned through deliberate practice, not compliance minimums.

This alignment reflects who we are and how we work. Cognician operates at the intersection of human behavior and technology; our clients trust us with their people and their data. Embedding the EU AI Act's principles into our governance gives our clients, and their own stakeholders, confidence that the AI practices running through our platform are held to a rigorous, globally recognized standard today and as regulation continues to evolve.

Proactively aligned

 

Certifications and Compliance

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

6-1

SOC 2 – Inherited via Microsoft Azure

Cognician does not hold a standalone SOC 2 report. Our platform is hosted entirely on Microsoft Azure, which maintains SOC 2 Type II certification across its infrastructure. Cognician's security controls are designed to operate within and complement Azure's environment. Microsoft's compliance document is available via the Azure Trust Center.

Inherited — Azure SOC 2 Type II

 

Cybersecurity, Risk and Threat Detection

See Our values

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

wired-outline-2263-alert-hover-pinch

Continuous Threat Monitoring

Real-time alerting and centralized logging provide continuous visibility across our environment. Anomalous activity is detected and escalated automatically, with structured investigation and rapid containment processes in place. 

wired-outline-2764-reliable-alt-hover-pinch

Vulnerability Management

Ongoing vulnerability identification, prioritization, and remediation runs continuously between scheduled assessments. All findings are formally tracked and resolved through structured governance processes.

wired-outline-19-magnifier-zoom-search-hover-spin-1

Incident Response

A formal incident response capability ensures rapid containment, structured investigation, and timely communication with affected parties in line with regulatory obligations.

wired-outline-2533-agile-hover-pinch

Risk Management

Risk assessment and management are core to our ISMS. Our risk-based approach – aligned to ISO and NIST – ensures cybersecurity investments are directed where they matter most and reviewed on a continuous basis.

Cloud Architecture

Frame 6-3

Microsoft

Azure

Frame 4-4

Datomic

Database

 

Frame 5-2

Clojure

Application Stack

 

Hosted on Microsoft Azure — designed for enterprise resilience
  Cloud platform
Microsoft Azure — enterprise SLA, multi-zone redundancy
  Database
Datomic — immutable, fully auditable data model
  Application stack
Clojure — functional, minimal attack surface
  Tenancy model
Multi-tenant SaaS with logical data separation per customer
  Network architecture
Segmented, default-deny with layered boundary controls
  Resilience
Automated scaling, regular backup & restoration validation

Independent Assurance

See Our values

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

no1

Annual ISO/IEC 27001 External Certification Audit

Conducted by an accredited certification body. Validates ingoing ISMS effectiveness and full control coverage.


 

See Our values

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

no2

Annual Internal Independant ISMS Audit

Internal audit function validates continuous control effectiveness and drives improvement between external cycles.


 

See Our values

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

no3

Annual Independent Penetration Testing

Aligned to industry standards. All findings formally tracked, prioritized, and remediated through structured governance.


 

See Our values

We build revenue-driving systems on HubSpot for businesses that are ready to grow - and keep on growing.

no4

Ongoing Vulnerability Identification and Remediation

Continuous scanning and real-time alerting ensure emerging threats are identified and addressed between scheduled assessments.


 

Contact Security

Security & Compliance team
Chief Information Security Officer · Cognician
For security questionnaires, resource requests, sub-processor enquiries, or RFP support — our security team responds directly.
AdobeStock_598799022-1

Explore Cognician!

 Book a call with us to discover ways to speed up change in your organization and make it stick.

Book a demo