Enterprise  ·  Business LineESEN
Cognikas Cloud · Security and architecture

Designed to pass your security team's review.

We show the architecture, the controls and the actual compliance status before the first technical meeting — what is in production and what is in progress, with no window dressing.

Six pillars

Our commitments, on one screen.

Isolation

Dedicated per-client deployment: VPC, database, compute and cache not shared with any other tenant.

Encryption

At rest (AES-256 via KMS, per-client key) and in transit (TLS 1.2+) across all flows, including backups and secrets.

Identity

Auth0 with SSO/SAML, MFA and RBAC, federated with the client's IdP (Okta, Azure AD, Google Workspace).

Auditing

Traceability of interactions, administrative access and configuration changes, exportable to the client's SIEM.

Residency

AWS LATAM regions (sa-east-1 by default) or whichever region the contract requires.

Subprocessors

Public, versioned list, with advance notice of changes and the right to object.

Controls

Network, identity, application and operations.

A summary of the dedicated deployment's controls. The full technical document is shared during the security review.

Network
  • Private VPC with no peering by default
  • WAF with OWASP Top 10 rules and rate limiting
  • Database with no public access
  • Optional site-to-site VPN / PrivateLink
Identity and access
  • SSO via SAML 2.0 / OIDC per client
  • MFA enforced on administrative roles
  • RBAC with predefined and custom roles
  • Cognikas access: just-in-time, client-approved, TTL ≤ 4h
Application
  • Row-level multi-tenant isolation (RLS)
  • Input validation and per-endpoint rate limiting
  • OWASP mitigations: SQLi, XSS, CSRF, SSRF
  • Secrets never in logs (middleware sanitization)
Operations
  • Structured logs with configurable retention
  • SIEM export (Splunk, Datadog, ELK)
  • Encrypted daily backups + point-in-time recovery
  • Critical security patches within ≤ 72h

BYOK:on the Custom tier, the client brings its own LLM provider keys (OpenAI, Anthropic, AWS Bedrock). Cognikas operates in passthrough mode: it neither stores nor sees the content sent to the model, and the client applies its own residency and compliance controls.

Compliance

Actual status, not aspirational.

Law 29733 (Peru)
Architecture and processes aligned
Aligned
LGPD (Brazil)
Architecture aligned
Aligned
LFPDPPP (Mexico)
Architecture aligned
Aligned
SOC 2 Type I
In preparation
In preparation
SOC 2 Type II
On the roadmap (after Type I)
Roadmap
ISO 27001
On the roadmap
Roadmap
PCI DSS
Not directly applicable: payment processing stays on the client's rail
Aligned

Cognikas is a young company and formal certifications are in progress — we would rather say so than dress it up. The architecture is designed in accordance with the frameworks listed, and we do not accept contracts that require controls the platform cannot deliver within the contract term.

For your security review

Three steps, zero friction.

  1. 01Review the public list of subprocessors and request the security documentation for your assessment.
  2. 02If your organization requires a specific DPA, we sign it as an addendum to the MSA before go-live.
  3. 03The full detail on architecture, RPO/RTO and incident response is shared under NDA during the technical review.