We host servers that talk to your Notion, GitHub, Stripe, and everything else. That's a lot of trust. Here's how we earn it.
TLS 1.3 between clients, us, and your handler. Envelope encryption at rest with per-region keys. Secrets never appear in logs.
OAuth for every MCP client, hardware-key MFA for staff, and least-privilege scopes for platform APIs. SSO + SCIM on Team.
Every action — deploy, rollback, secret rotation, OAuth grant — is written to an immutable audit log with 1-year retention on Team.
Each MCP server runs in its own V8 isolate; secrets and network are scoped per server. Team tier adds VPC egress and dedicated pools.
We're honest about what we do and don't cover. SOC 2 is in audit; certification expected Q3 2026.
Staff access to production requires a signed change ticket. No shared credentials, ever. All access sessions expire in 8 hours.
Signing keys rotate every 30 days automatically. Long-lived tokens (Team OIDC clients) rotate every 90 days.
Every merge runs SBOM diff + vulnerability scan; production dependencies pinned to hash.
Rewards up to $5,000 for critical issues. Report responsibly to [email protected].
Rewards up to $5,000 for critical issues, with a scope covering cognoverge.com, app.cognoverge.com, and *.cognoverge.dev deployments.
[email protected]A full list of the vendors we use for compute, storage, and payments — updated whenever it changes.
View subprocessors