Loading...
Loading...
Encryption in transit, role-based access controls, tenant separation, audit logging for key actions, and data export or deletion workflows. SOC 2 readiness, responsible AI governance, and audit-readiness processes are in progress.
Security
Controls designed to protect candidate and employee data through encryption, access management, tenant separation, and logging.
TLS 1.2+ on the wire and AES-256 on disk so sensitive hiring and employee data is protected in transit and at rest.
RBAC, MFA, and Enterprise SSO so the right people see the right data with fewer access surprises as you scale.
Customer data stays separated at the application layer so another organization's activity never mixes with yours.
Key actions are logged. Enterprise teams get full trails for reviews, investigations, and compliance workflows.
Regular reviews, dependency checks, and a disclosure path so problems are prioritized and addressed.
Data export or deletion workflows to support your data governance policies and regulatory requirements.
Privacy
Plain language so employees, candidates, and legal teams get clarity on data practices.
You provide what the product needs to run: accounts, candidates, assessments, and training data. We collect light usage signals to improve the service, not to sell profiles.
We run the service and improve it for you. We do not sell your data. We do not train shared AI models on your candidates or employees for other customers.
Data stays while your account is active. After you close, we hold it 30 days for export, then delete. Want it gone sooner? Ask anytime.
Infrastructure, email, and analytics vendors are under contract to meet our standards so your trust extends to the partners we select.
Compliance
Compliance obligations may depend on the customer's location, configuration, data practices, notices, hiring workflows, and use of AI features. Customers should review their obligations with legal counsel.
We encrypt data at rest (AES-256) and in transit (TLS 1.2+), enforce RBAC with MFA, and offer DPAs on request. Designed with GDPR principles in mind.
Enterprise teams can discuss regional hosting so residency matches your policies.
Pull your data or request deletion from settings or support. No runaround when someone requests their file.
Screening uses your data to serve you only. We do not train shared models on your applicant pool.
Compliance Status
Transparency about where we are today and what is in progress.
SOC 2 readiness, responsible AI governance, and audit-readiness processes are in progress. We do not currently hold SOC 2, NYC AEDT, EU AI Act, or GDPR certifications.
SOC 2 Type I readiness is in progress. Formal third-party attestation has not yet been completed. Contact us for current timeline and interim security documentation.
Cognaium is building workflows to support customer readiness for AI hiring notice, review, and audit obligations, including jurisdictions such as NYC where applicable.
Certain Cognaium features may fall within employment-related high-risk AI categories under the EU AI Act depending on configuration and use. Governance controls are in progress.
Security Contact
Responsible disclosure keeps everyone safer. Report issues and we prioritize fixes and clear communication.
Email support@cognaium.com and we aim to reply within 48 hours.
DPAs, access requests, or privacy questions: support@cognaium.com