Built for sensitive deals
Security that compliance teams trust.
M&A data is sensitive, and a leak carries real legal consequences. We built CogniSuite with security as the foundation: a separate encrypted database per deal, a watermark on every view, and a complete audit trail.
Compliance status
- SOC 2 Type II In progress
- Currently self-assessed against the AICPA Trust Services Criteria; a Type II report is underway.
- FIPS 140-3 Validated
- Data is encrypted with a FIPS 140-3 validated cryptographic module.
- GDPR Aligned
- Designed to meet GDPR obligations for handling EU personal data.
- ISO 27001 Aligned
- Security controls designed to align with ISO 27001 practices.
§01 · Cryptography
Encryption
FIPS 140-3 validated cryptography
Deal data is encrypted with AES-256-GCM using a FIPS 140-3 validated cryptographic module, the same standard US federal agencies require.
- Per-deal encryption keys
- Each deal is encrypted with its own key derived from a master key. One deal's compromise does not reach any other.
- Encrypted at rest
- File contents, metadata, and comments are all encrypted before anything touches disk.
- Encrypted in transit
- TLS 1.3 on every connection. Nothing travels in the clear.
Master key
Held in a hardware security module
derives a key per deal
Deal A
AES-256-GCM
Deal B
AES-256-GCM
Deal C
AES-256-GCM
Encrypted at rest
§02 · Watermarks
Traceability
Dynamic watermarking
Every document is watermarked with the viewer's identity at the moment it is served. If a file leaks, the stamp shows who it was served to.
- Generated per view
- The stamp carries the viewer's email, organization, deal ID, and the time of access.
- Every file type
- PDF, Word, Excel, images, and video. The method adapts to each format.
- Configurable per project
- Control the watermark's content, position, and visibility for each deal.
§03 · Access
Access control
Defense in depth
Every access decision runs through one enforcement point. Access is layered, and least privilege is the default.
- Single sign-on
- OpenID Connect. Connect your identity provider and enforce your own authentication policies. Sign-in is restricted to the email domains you configure, so your provider can only assert people who belong to your firm.
- Per-deal databases
- Every deal is a separate encrypted database, not a partition of a shared one. A query in one deal cannot reach another deal's material by construction, not by a permission check.
- Passwordless authentication
- Single-use email passcodes with automatic lockout after repeated failed attempts — no reusable passwords to phish or leak.
- Role-based access
- Admin, contributor, participant, and observer roles, scoped per workstream, least privilege by default.
- Session management
- Server-side session tokens, revoked immediately when a user's access is changed or removed.
- IP allowlisting
- Restrict access to specific IP ranges, such as a corporate network or a named participant location.
- Download controls
- Disable downloads entirely or allow view-only access, per document or across a project.
§04 · The trail
Accountability
A complete audit trail
Every action is logged. Access grants, file views, downloads, and status changes are each recorded with the actor, the exact time, and the originating IP address.
- Real-time activity monitoring
- Exportable audit reports
- Anomaly-detection alerts
- Seven-year retention for compliance
Every entry also records the exact time and originating IP address.
§05 · Infrastructure
Resilience
Infrastructure built for sensitive data
Dedicated, continuously monitored infrastructure with redundant storage.
- Redundant storage
- Data is stored redundantly with automated, regularly tested backups.
- Continuous monitoring
- Systems are monitored around the clock, with alerting on anomalous activity.
- Multiple regions
- Deployed across more than one geographic region for resilience.
- Incident response
- A documented incident-response process, including notification to affected customers.
Questions about security?
Talk to our security team. We are glad to answer technical questions and share documentation.