Skip to content

Seven questions to put to a vendor, and our answers

Encryption at rest stops an attacker reading raw disks. It does not stop a bidder being granted a folder built for someone else, or a file leaving inside a bulk download. Those are the failures that damage a live process. Expect numbers, not adjectives.

Which cryptographic module, and what is its CMVP certificate number?

Ours is AES-256-GCM with keys derived by HKDF-SHA256. The mode is authenticated, so altered ciphertext fails to decrypt rather than returning altered content. We hold no CMVP certificate of our own and do not claim one.

Is your application validated, or does it call a validated module?

A certificate covers a module, never a whole product. A vendor whose application links against a validated module has not had its application validated, ours included.

What is the key hierarchy, and who can reach the root material?

Ours are derived by purpose, with HKDF, from one master key. That is one hierarchy for the platform, not one key per deal, and we say so rather than advertise per-deal keys we do not have. Ask any vendor claiming per-deal keys to derive two of them in front of you, and ask us to walk you through our key handling under NDA. /security is our authoritative answer.

What is encrypted at rest beyond document bytes?

For us, each entry's summary and metadata blob, so document and folder names are not held in plaintext in the deal database.

Is the audit trail tamper-evident?

Ours is not. Audit rows are readable columns with no hash chain and no signature, and the trail is visible to the advising firm rather than to counterparties. Treat it as operational evidence, not forensic proof.

Does the same permission check govern bulk download and AI answers?

For us, yes. One retrieval path applies the asking user's own folder permissions before a document becomes a source, and chat, Q&A drafting, request drafting and request matching all use it. The exception is the keyword step that suggests supporting files when we publish a Q&A entry, which is open to advisory roles only. Export is gated separately from reading, so a view only folder blocks the single download, the viewer's native stream and each file inside a bulk zip.

Where does plaintext exist, and which third parties receive document content?

Preview, watermarked renditions, text extraction and search all decrypt. Document text also goes to our model provider. Read the retention terms of whoever answers.

Why "military-grade encryption" means nothing

AES is a public standard that anyone can implement well or badly, published by NIST as FIPS 197. CNSS Policy No. 15 states that all AES key lengths protect classified information up to SECRET, that TOP SECRET requires 192 or 256 bit keys, and that implementations protecting national security systems must be certified by NSA. The weight sits on certification of the implementation, not on the algorithm name.

The phrase names a cipher choice common to nearly every product, and says nothing about key scope, key custody, where plaintext exists or who can reach it. An attacker holding a valid session does not need to break AES. Neither does a participant granted a folder they should never have been given.

What a validation certificate covers

The scope is a cryptographic module at a fixed version, tested in a stated operational environment. Change the version or platform, or call the same library in a non-approved mode, and the certificate stops describing what you run. FIPS 140-3 defines four security levels; Level 1, the common grade for software, says little about physical protection. CMVP conditions use of the validation phrases on naming the certificate, so "FIPS 140-3 Validated" should carry a number you can check.

The 22 September 2026 deadline

Every remaining FIPS 140-2 certificate moves to the CMVP Historical List on 22 September 2026, so a vendor leaning on one needs a new answer. The Cryptographic Module Validation Program is run by NIST and the Canadian Centre for Cyber Security; the current standard is FIPS 140-3 and the transition timeline has been public for years.

Historical is not revocation. CMVP keeps a separate Revoked status for validations that can no longer be referenced for compliance. Its guidance on Historical is weaker: agencies should not put those modules in new systems, though "CMVP supports the purchase and use of these modules for existing systems." Outside federal procurement it is a reason to ask the questions above, not a disqualifier.

Where we fall short

  • Watermark coverage. Serve-time watermarks cover PDF, Word, images, Excel and PowerPoint, and a format we cannot mark is refused rather than served clean. The mark is visible provenance, not forensic marking, and a recipient can strip it.
  • Permissive defaults. Folder restrictions are configuration you apply, not a starting posture.
  • Retrieval reaches view only material. Any folder you have some access to can be quoted in an AI answer, including documents you may only view watermarked.
  • Prompt-level defences. Guarding against instructions hidden inside documents is mitigation, not a boundary.

The boundary we stand behind is structural: each deal is a physically separate database on its own subdomain, so one deal's material cannot be reached from another by construction rather than by rule.

Folder access for each party is granted per organisation and per user from the deal's parties screen.
Folder access for each party is granted per organisation and per user from the deal's parties screen.

Put these questions to us before you run a process on the platform.

General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.

← All articles