Security you can check.
Security and sovereignty are design constraints we hold from the first commit, and most of them run as CI gates. There is no closing phase.
Compliance. Product. Infrastructure. Operations.
Compliance
The questionnaires procurement and security teams ask for. Send us yours and we answer it; each card says whether we already hold that one, and the date it was last reviewed.
Product
What the software itself enforces, on every request.
Infrastructure
Where systems run and how tenants are kept apart.
Operations
How every change ships.
Every artifact, listed.
Public documents open directly. Gated ones arrive by email once we know who’s asking. No artifact routes to a generic contact form.
Request a gated artifact
Tell us who you are and which document you need. We’ll send it over. NDAs welcome.
The gates run in CI.
Most trust pages list aspirations. Ours points at checks that pass or fail in CI: quality, isolation, supply-chain, and security gates, plus a tenant-isolation harness that writes its verdict to the database. No badge images. All of it runs on our own platform, so read it as the standard we hold rather than as a record of client deliveries. The isolation verdict on our status page is the one claim here you do not have to take on trust: our CI writes it, and that page reads it back.
What we don’t claim yet
SOC 2 and ISO 27001 are on our roadmap, not our wall. Until an auditor signs, what you get are the controls themselves: RLS-forced tables, zero-retention model calls, and a validation gate on every commit. We hold no completed security questionnaire yet either — send us the one your procurement team uses and we answer it. The second limit is delivery history. We have not yet delivered a client system into production, so everything on this page evidences the standard we build to, not a record of systems already running in someone else’s production.
Who touches the data.
This website and the Cogvera Hub. Our own platform, which is also where client data sits during an engagement. Database, authentication and file storage run in ap-southeast-2. The site you are reading is served by Vercel, whose compute sits in the United States, and our AI features call a US model provider under zero-retention terms. The register below names every third party involved and marks the ones that are not onshore.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, auth & storage | ap-southeast-2 (Sydney) |
| AWS | Infrastructure underlying Supabase | ap-southeast-2 (Sydney) |
| Vercel | Hosting & CDN | Global edge · US computeoffshore |
| Anthropic | AI inference (zero data retention) | USoffshore |
| Stripe | Billing | US · globaloffshore |
| Resend | Transactional email | USoffshore |
| Sentry | Error monitoring | USoffshore |
| Deepgram | Voice transcription | USoffshore |
Systems we build for clients. Set per engagement and written into the agreement before the first commit. The default is a data plane in ap-southeast-2 with model calls under zero-retention terms. A sovereign build drops the model provider entirely and runs on hardware you own.
What changed, and when.
Sovereign reference architecture
Sovereign reference architecture added to the document library (request access), backing the sovereign offering published at /what-we-build.
Trust centre launched
Document library, subprocessor register, dated updates feed, and the responsible-disclosure route published at /trust and /.well-known/security.txt.
Isolation badge made public
The RLS isolation harness result became publicly readable through a definer RPC (trust_badge_public). Live proof without a staff session.
Public intake hardened
Marketing contact submissions moved to a SECURITY DEFINER intake RPC with per-IP rate limiting; the leads table has no anonymous write policy.
Spotted something? Tell us.
Found a vulnerability in anything we run? Email us directly. No forms, no triage bots. We acknowledge reports within three business days, keep you informed through to resolution, and credit good-faith research if you want the credit.
- Contact
- info@cogveralabs.ai
- Acknowledged within
- three business days
- Machine-readable
- /.well-known/security.txt
Bring us the work. We’ll bring the governance.
Two hours, your team, the real work. Everything on this page ships with it.