Regulatory Compliance

Compliance & Certifications

Cognis Digital maintains rigorous compliance with industry standards and regulations to protect your data and support your compliance requirements.

Compliance Frameworks

SOC 2 Type II

Certified

Service Organization Control 2 Type II certification demonstrates our commitment to security, availability, processing integrity, confidentiality, and privacy.

  • Annual third-party audit
  • Continuous monitoring of controls
  • Covers security and availability criteria
  • Report available under NDA

GDPR

Compliant

We comply with the General Data Protection Regulation for processing personal data of EU residents.

  • Data Processing Agreements available
  • Standard Contractual Clauses for transfers
  • Privacy by design principles
  • Data subject rights supported

CCPA/CPRA

Compliant

We comply with the California Consumer Privacy Act and California Privacy Rights Act.

  • Consumer rights requests honored
  • Do not sell personal information
  • Privacy notice provided
  • Service provider agreements in place

HIPAA

Available

HIPAA-compliant deployment available for healthcare customers handling protected health information.

  • Business Associate Agreements available
  • PHI safeguards implemented
  • Audit logging for compliance
  • Enterprise plan required

ISO 27001

In Progress

We are working toward ISO 27001 certification for our information security management system.

  • ISMS framework implemented
  • Risk assessment procedures
  • Continuous improvement process
  • Expected certification: Q3 2026

PCI DSS

Compliant

Payment card data is handled by PCI DSS compliant payment processors. We do not store card data.

  • Stripe handles payment processing
  • No card data stored on our servers
  • Secure payment flows
  • SAQ A compliance

Documentation

Security Whitepaper

PDF - ~50 KB

Data Processing Agreement

PDF - ~40 KB

Privacy Policy

Web

Terms of Service

Web

* SOC 2 reports and security assessments available under NDA.

Data Residency

All data is processed and stored within the United States.

United States

Primary

AWS us-east-1, us-west-2

Data Processing & Privacy

Your Rights

  • Access your personal data
  • Correct inaccurate data
  • Request data deletion
  • Export your data (portability)
  • Object to certain processing
  • Withdraw consent

Our Commitments

  • No selling of personal data
  • Minimal data collection
  • Clear retention policies
  • Secure data handling
  • Transparent practices
  • Prompt breach notification

Subprocessors

We use carefully vetted third-party service providers to deliver our Services. All subprocessors are contractually bound to protect your data.

ProviderPurposeLocation
Amazon Web ServicesCloud infrastructureUS, EU
SupabaseDatabase and authenticationUS
StripePayment processingUS

Compliance Questions?

Our compliance team can provide documentation, complete security questionnaires, and support your vendor assessment process.