Security
Last updated: 20 July 2026
This page is under final legal review and may be updated before it is finalised.
Security and privacy are built into how Cogent² (Cogent2 Limited) is designed and operated. This page summarises the main measures we take to protect your data. It sits alongside our Privacy Policy, Data Processing Agreement and Sub-processors.
Data minimisation by design
Our integration platform does not persist raw customer payload data. Incoming data passes through a redaction pipeline that strips credential-shaped and PII-shaped fields before anything is stored, we observe the structure of data only and never its values, and content sent to our AI provider is redacted on the same basis. Files handled by our EDI service are necessarily stored whole to be validated, translated and delivered, and are protected by encryption, access control, and automatic deletion on a rolling 30-day basis.
Encryption
Data is encrypted in transit using TLS. Data at rest is protected by our hosting providers' managed encryption, and sensitive credentials such as per-account integration keys are additionally encrypted at rest using authenticated encryption with managed key rotation.
Access control and tenant isolation
We enforce role-based access control with least-privilege roles. Account scoping keeps each customer's data isolated so one account cannot access another's, and this isolation is verified with automated tests as part of our development process. Administrative access is restricted and can be protected with multi-factor authentication.
Hosting
We host our application and database in the EU region (Railway and Supabase), and our EDI file storage in the Amazon Web Services EU region. Our full list of sub-processors, with their purpose and location, is on our Sub-processors page.
Artificial intelligence
Where our AI features process content, that content is used only to generate your response and is not used by our AI provider (Anthropic, PBC) to train its models under the terms we contract on. Personal data from your connected systems that passes through our integration platform is redacted as described above before storage.
Certifications of our providers
Our platform is built on established infrastructure and integration providers that maintain recognised security certifications. Patchworks, the integration platform behind our iPaaS, maintains ISO 27001 and SOC 2, and our cloud providers maintain their own certifications. Cogent² itself is not currently independently certified to those standards; where a customer needs formal assurance, we can share the relevant provider reports and answer a security questionnaire.
Monitoring and resilience
We log and monitor platform operations, alert on integration failures and suspicious activity, and maintain back-ups and documented recovery processes for platform data.
Sub-processors
We engage a small number of sub-processors under data-protection terms, and give customers at least 30 days' notice before adding or replacing one. The current list is on our Sub-processors page.
Insurance
We maintain appropriate professional indemnity and cyber-liability insurance for a business of our size and activities.
Reporting a vulnerability
If you believe you have found a security vulnerability, please tell us at privacy@cogent2.com so we can investigate. Please give us a reasonable opportunity to respond before any public disclosure, and do not access, modify or delete data that is not your own.
Contact
For security or privacy questions, contact privacy@cogent2.com.