Trust & Security | Cognethics

Built for regulated industries. Verifiable, not just promised.

When you are accountable for the data, “trust us” is not enough. The A4 Platform is built so you can prove what happened, keep your data where your rules require it, and sign in with the identity provider you already run.

Denied unless you allow itEvery action on the recordWalled off to your organization
app.cognethics.com/audit/permissions

The platform shows exactly what was attempted and blocked — per person, per action, in real time.

PERMISSIONS THAT HOLD

Denied unless you allow it — resolved down your whole organization, per person.

Every action — by a person or an AI agent acting on their behalf — is checked against your permission rules before it happens. An agent can only ever touch what the person it acts for is allowed to touch, and nothing more.

Permissions resolve through your organization’s full hierarchy: a department inherits from a division, a division from the top, and individual overrides apply at any level. There is no way for “just ask the AI” to route around your controls — because the controls are enforced, not advised.

An agent can only touch what your permissions allow — resolved per person, denied unless you allow it.
GRANULAR ROLES

Your people get exactly what their role requires — and nothing beyond it.

Roles are configured at the organization level, not per person, so adding someone to the right group is all it takes. Remove the group membership and access ends — instantly, everywhere, with no manual cleanup list.

app.cognethics.com/settings/roles

Roles, groups, and permission assignments — the full picture in one place.

THE RECORD THAT HOLDS UP

Every decision is on the record — and the record can’t be quietly rewritten.

Most systems ask you to believe their logs. A4 lets you verify them.

Every action that matters — who was allowed to do what, what an AI agent did, every approval, every escalation, every change to a policy — lands in a single, continuous record. That record is built so that each entry is mathematically linked to the one before it. Alter, delete, or back-date a single entry — even directly in the database — and the chain breaks at exactly that point. A check run on demand pinpoints the first entry that was touched.

No quiet edits. No after-the-fact cleanup. When you tell an auditor what happened, you can show them — and they can confirm it without taking your word for it.

Every action is written to a record where altering a single entry breaks the chain — and the break is detectable.
YOUR DATA, YOUR WALLS

Isolated by organization. Encrypted in transit and at rest. We never train on your data.

Your data, your people, and your record stay inside your organization. Nothing crosses the boundary into anyone else’s account.

ISOLATION & ENCRYPTION

Walled off completely.

Each organization runs inside its own isolated boundary — enforced by construction at the database, query, and tool-handler layers, not by optional filters a developer could forget. Data is encrypted at rest with AES-256 via AWS KMS, and sensitive data is wrapped with a dedicated per-tenant key that rotates automatically, so every account is cryptographically separated. Traffic is encrypted in transit with TLS 1.2+, and protected health information gets an additional layer of application-level encryption on top. For strict cryptographic requirements, a dedicated FIPS-mode environment is available.

YOUR MODEL, YOUR CHOICE

Your data is yours. Always.

Bring your own AI model and swap it whenever the market moves. The line we never cross: we never train on your data. It is used to serve you, and only you. Nothing you put into the platform leaves to improve a shared model.

SIGN IN THE WAY YOU ALREADY DO

The single sign-on you already run — Okta, Entra, Google, and others.

No new password to manage, no separate user list to keep in sync. A4 plugs into your existing sign-on, so your people authenticate the way they already do, under the access policies you already enforce.

Self-serve SAML 2.0 single sign-on and SCIM 2.0 provisioning are available to every organization, configured in your admin console, with OIDC federation supported. When someone joins, they are granted access automatically. When they leave, that access is removed automatically — no manual onboarding lists, no stale accounts lingering after an offboarding. You can also require multi-factor authentication (TOTP) for everyone in your organization through a single policy, so your directory stays the single source of truth.

app.cognethics.com/settings/sso

Enterprise single sign-on on one page — SAML 2.0, domain routing, SCIM provisioning, and a full SAML auth log, configured in your own admin console.

PROVISIONING ON AUTOPILOT

Joiners provisioned, leavers deprovisioned — automatically.

Your identity provider drives the user list. A4 exposes a standards-based SCIM 2.0 endpoint (RFC 7644), protected by a bearer token you mint and rotate yourself — A4 stores only a hash of it, never the value. Turn on user and group sync and people are created, mapped to the right roles, and deactivated the moment your directory says so — no manual onboarding list, no stale account left behind.

app.cognethics.com/settings/scim

Standards-based SCIM 2.0 provisioning — users and groups synced from your identity provider, with a bearer token you mint and rotate yourself.

IDENTITY GOVERNANCE

Your directory groups become roles — and the rules that gate access.

Map an identity-provider group to a role, an organization, or the right to run an agent or persona — the grant stays inert until a matching person signs in or syncs. Conditional-access policies gate who can sign in and what an agent can dispatch, org-scoped and off by default until you turn them on. Every grant and every access decision is recorded, with the matched policy and the reason it applied.

app.cognethics.com/settings/identity

Identity-provider groups mapped to roles and org membership, conditional-access policies gating sign-in and agent dispatch — every grant and decision on the record.

COMPLIANCE-READY

Built for the frameworks your industry holds you to.

Security and privacy are part of how A4 is built — with controls mapped to the SOC 2 Trust Services Criteria and the standards you are measured against, not bolted on after the fact.

HEALTHCARE & HIPAA

A Business Associate Agreement, ready to sign.

Protected health information is encrypted, access is permission-controlled, and every touch is recorded. A Business Associate Agreement with our cloud provider is executed. Customer BAAs are available on request — no back-and-forth required.

PRIVACY — GDPR, CCPA & LGPD

Privacy rights handled, with the paperwork ready.

Collect only what is needed. Honor right-to-erasure, access, and portability requests across GDPR, CCPA, and LGPD. Generate Article 30 ROPA exports from your processing-activity register, and sign a Data Processing Addendum with Standard Contractual Clauses. Data-processing agreements are in place for every provider who touches your data.

Our controls map to the SOC 2 Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy. Need the detailed control mappings for a security or procurement review? Request our security overview and we will route it to the right team.

YOUR REGION. YOUR DATA. NO LOCK-IN.

Data residency, resilience, and a clean exit — all built in.

Data residency is not a setting buried in a contract. You choose the region, and your data stays there.

REGION & RESILIENCE

Pick your region. We keep it running.

Each deployment runs in the cloud region you select, across multiple independent availability zones. For deployments whose primary region is in the United States, your data is continuously replicated to a second AWS region kept ready as a hot standby — so a regional outage is something you recover from, not something that stops you. Prefer to run it yourself? A self-hosted or on-premises deployment is available.

EXPORT & PORTABILITY

Export everything, anytime. No lock-in.

Your data belongs to you, and you can take it out whenever you want — not just at the end of a contract. Documents, records, audit logs, and compliance artifacts all export in standard formats your other systems can read. Every export is itself recorded, so you always have a clean account of who took what, and when.

TRANSPARENCY

The providers we use to run the platform — all named, all under agreement.

We are open about who touches your data. These are the providers we rely on to run A4 — each one under a formal data-processing agreement, and published as a live registry so every change is announced the moment it lands.

Amazon Web Services (AWS)
The secure cloud your deployment runs on — compute, storage, networking, and encryption — in the region you select. Covered by an executed Business Associate Agreement for healthcare workloads.
Anthropic
The primary AI behind the platform’s assistants and agents. Content is encrypted in transit, and is never used to train external models.
Google
Used for narrow, specialized data-extraction tasks — reading details out of documents like invoices and clinical statements — under a data-processing agreement.
Cloudflare
Protects and accelerates traffic to the platform. It sees only request metadata — never your documents, records, or database content.
TALK TO US

Bring your security team. We’ll show you the proof.

We are glad to walk your security, compliance, and procurement teams through how A4 protects your data — in as much depth as your review requires. Request our security overview, or bring your questions and we will answer them directly.

Healthcare BAA, data-processing agreement, or a vendor questionnaire to complete? Tell us the topic and we will route it to the right team.