Compliance & Certifications
Cognis Digital maintains rigorous compliance with industry standards and regulations to protect your data and support your compliance requirements.
Compliance Frameworks
SOC 2 Type II
CertifiedService Organization Control 2 Type II certification demonstrates our commitment to security, availability, processing integrity, confidentiality, and privacy.
- Annual third-party audit
- Continuous monitoring of controls
- Covers security and availability criteria
- Report available under NDA
GDPR
CompliantWe comply with the General Data Protection Regulation for processing personal data of EU residents.
- Data Processing Agreements available
- Standard Contractual Clauses for transfers
- Privacy by design principles
- Data subject rights supported
CCPA/CPRA
CompliantWe comply with the California Consumer Privacy Act and California Privacy Rights Act.
- Consumer rights requests honored
- Do not sell personal information
- Privacy notice provided
- Service provider agreements in place
HIPAA
AvailableHIPAA-compliant deployment available for healthcare customers handling protected health information.
- Business Associate Agreements available
- PHI safeguards implemented
- Audit logging for compliance
- Enterprise plan required
ISO 27001
In ProgressWe are working toward ISO 27001 certification for our information security management system.
- ISMS framework implemented
- Risk assessment procedures
- Continuous improvement process
- Expected certification: Q3 2026
PCI DSS
CompliantPayment card data is handled by PCI DSS compliant payment processors. We do not store card data.
- Stripe handles payment processing
- No card data stored on our servers
- Secure payment flows
- SAQ A compliance
Data Processing & Privacy
Your Rights
- Access your personal data
- Correct inaccurate data
- Request data deletion
- Export your data (portability)
- Object to certain processing
- Withdraw consent
Our Commitments
- No selling of personal data
- Minimal data collection
- Clear retention policies
- Secure data handling
- Transparent practices
- Prompt breach notification
Subprocessors
We use carefully vetted third-party service providers to deliver our Services. All subprocessors are contractually bound to protect your data.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure | US, EU |
| Supabase | Database and authentication | US |
| Stripe | Payment processing | US |
Compliance Questions?
Our compliance team can provide documentation, complete security questionnaires, and support your vendor assessment process.