Security
Limiting what one compromised account can reach in a deal room
By the CogniSuite team
What one account can reach
If one ordinary account is misused, how much confidential material does it reach? In CogniSuite, one deal.
- One deal, one database. Every transaction is a separate database file on its own subdomain, with its own users, sessions, grants and audit log. A session on one deal is not a session on another.
- Then folder by folder. Every folder resolves to a grade for the person asking: full, watermark, view or none, plus a separate upload right.
- Reading and taking are separate. A view-only folder opens in the viewer; its bytes never export, including per file inside a bulk ZIP.
- AI reads through the same check. Chat, search, Q&A drafting, request drafting and request matching retrieve through one path that applies the folder check before a document is admitted.
Folder grades scope the client and counterparties, not your own deal team.
The SEC case and the FBI advisory
SEC, 6 May 2026. The SEC charged 21 individuals over an alleged insider trading scheme. The complaint alleges an M&A attorney misappropriated clients' material nonpublic information across more than twelve pending transactions. Nothing is proven; he has pleaded not guilty. Reporting on the complaint focused on document management at the firms where he worked, including matters he was allegedly not staffed on. Nothing was broken into. Valid credentials reached matters the holder had no role on.
FBI FLASH-20260526-01, 26 May 2026. The advisory describes the Silent Ransom Group, also tracked as Luna Moth: staff are called, or phished into calling back, then someone posing as internal IT support talks them into granting a remote desktop session. The FBI says the group has targeted US-based law firms since spring 2023 and, once inside, minimally escalates before pivoting to exfiltration. What the person on the phone holds is enough.
How access is scoped
- Per-deal grant first. A grant sets read, write, delete or manage rights on the transaction at all. This layer scopes your own bankers and lawyers.
- Precedence inside a deal. Per-user beats per-organisation, beats the nearest ancestor folder, beats the organisation default. Unset all the way up, a folder resolves to internal, so a new folder is never bidder-visible by accident.
- Org-specific folders. A folder scoped to one organisation is readable by it alone, not every buyer.
- Deal-side aware. The room knows whether you sit buy-side or sell-side and keeps the counterparty out of the internal room by default. You can still open a single internal folder to the counterparty.
- Watermarks at serve time. The stored copy stays clean; the mark carries the viewer's name, organisation and a UTC timestamp, and a folder setting overrides the organisation default.
- Check it before documents go in. View the room as a specific counterparty organisation; the engine resolves against that org rather than hiding things in the interface.
- On the record. Views, downloads including via ZIP, permission changes and AI questions are logged, filterable and CSV-exportable. See /security.

Can the AI widen access?
Can the assistant surface a document I cannot open? No. One retrieval function embeds the question, scores stored document vectors, and applies the folder read check before admitting a document.
What about a draft going to the other side? Grounding narrows to documents every counterparty organisation able to see that request list may read, an intersection rather than a union, not what the drafting banker can see.
And if ownership of the list is unclear? It denies, rather than falling back to the banker's own access.
What this does not solve
- Your own firm. Deal team roles resolve to full access before folder grants are consulted, so who is added to the deal governs internal reach.
- Authorised misuse. Someone staffed on a matter can read it, and nothing here tells you the reason is bad.
- Authentication. A handed-over session looks like an authorised user. Tokens are not bound to a device or address, so a stolen one works anywhere until it expires or is revoked.
- The record's weight. An advisor oversight tool: a buyer or seller cannot review their own activity, and it is not cryptographically tamper-evident.
- Watermark strength. Visible, not forensic: it shows who was served a copy, and does not survive a photograph or retyping.
- Defaults. A room left on defaults has every control above available and none in effect. The grades bite once someone sets them.
- Grades in retrieval. Retrieval admits any folder above none, so a quote can come from a document that party may view but not download. Set none rather than view where that matters.
None of this prevents a compromise. It limits how much material one account reaches when one happens.
General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.