Encryption Everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups and file storage use server-side encryption with managed keys.
Security & privacy
Cognuum is built for professionals who demand confidentiality. Here is how we protect your data, your research, and your privacy.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Database backups and file storage use server-side encryption with managed keys.
Supabase Auth with Row Level Security (RLS) enforces per-user data isolation at the database layer. Every API endpoint validates JWTs before processing.
We collect only what is necessary to deliver the product. No analytics trackers, no third-party ad pixels. Your research and portfolio data are never sold or shared.
Prompts sent to LLM providers are governed by commercial API terms that prohibit training on inputs. OpenAI conversation storage is disabled on every call. No user-identifying metadata is passed to inference endpoints.
Hosted on SOC 2-compliant infrastructure. Network-level firewalls, automated vulnerability scanning, and immutable deployments protect the platform.
Independent security researchers conduct penetration tests through our Cobalt.io program. Findings are triaged and remediated on a continuous basis.
Every layer of the stack enforces isolation and access control — from the network edge to the database row.
Every database query is scoped to the authenticated user via Postgres RLS policies.
Edge functions enforce auth checks independently of database policies — no single point of failure.
Strict origin allowlists on every API endpoint — no wildcard origins.
Service roles are scoped to the minimum permissions required for each function.
Third-party services that process data on our behalf. We vet each provider for security practices and data handling commitments.
Provider
Purpose
Location
Privacy
Cognuum uses multiple AI providers to power its intelligence features. Here is how we protect your data across all of them.
If you believe you have found a security vulnerability in Cognuum, we encourage responsible disclosure. Please contact us directly — do not open a public issue.
Related policies