Skip to main content
CognitaGRC
PlatformPricingDocsTrust
Sign inOpen product →
Cognita

The intelligence layer for AI compliance. Built for the post-EU-AI-Act world.

ISO 42001EU AI ActNIST AI RMF

Product

PricingTrust CenterDocumentation

Frameworks

ISO/IEC 42001EU AI ActNIST AI RMF

Resources

Product demoDocsTrustSecurity

Company

SecurityPrivacyContact
© 2026 Cognita, Inc. · cognitagrc.ioChecking status…
TRUST CENTER

We run our own governance on our own platform.

Cognita's policies, risk register, and audit trail live on the same hash-chained, Merkle-anchored ledger we sell. Formal third-party certifications are on our roadmap — we are not yet certified, and we won't claim otherwise. What's below is what is true today, and how to verify it yourself.

SOC 2 Type II
roadmap
Formal SOC 2 Type II certification is on our roadmap. Not yet certified.
ISO 27001
roadmap
Formal ISO/IEC 27001 certification is on our roadmap. Not yet certified.
ISO 42001
practices
We manage our own AIMS on the Cognita platform. Self-managed — not yet registrar-audited.
GDPR
practices
GDPR-aligned practices: PII redaction before ledger writes, EU data-residency pools, DPA available on request.
CCPA
practices
Aligned practices. No formal attestation.
HIPAA
roadmap
Sovereign tier only — on the roadmap. Not offered today.
MULTI-FRAMEWORK READINESS — THE PRODUCT

Collect evidence once. Prepare for several frameworks.

The percentages below are computed live from our control crosswalk — the share of one framework's requirements that evidence collected for another already reaches. They describe evidence REUSE for readiness preparation; certificates and SOC 2 reports are issued only by independent third parties.

This is a readiness assessment prepared to support an external examination. It is not an attestation, not a SOC 2 report, and not an auditor's opinion. SOC 2 reports are issued only by a licensed CPA firm after its own independent examination.
56%
of SOC 2 Trust Services Criteria pre-evidenced by ISO 27001 + ISO 42001 controls
This is a readiness assessment prepared to support an external audit. It is not a certification, not an attestation, and not a conformity decision. ISO/IEC 27001 certificates are issued only by an accredited certification body after its own independent audit.
100%
of ISO 27001 Annex A controls pre-evidenced by SOC 2 criteria
This is a readiness crosswalk prepared to support an external audit. It is not a certification, not an attestation, and not a conformity decision. ISO/IEC 42001 certificates are issued only by an accredited certification body after its own independent audit.
64%
of ISO 42001 Annex A controls pre-evidenced by ISO 27001 + SOC 2 — the AI-specific remainder is the work

Method: direct control-to-control mappings only (no transitive credit, management-system clauses excluded from scoring). The same crosswalk powers the readiness engine inside the product.

WHAT OUR OWN LEDGER RECORDS · ILLUSTRATIVE

Illustrative examples of the control events the platform records on its hash-chained ledger — not a live feed. Ask us for a walkthrough of the real one.

Quarterly access review recorded with evidenceISO 27001 A.5.18
Backup integrity check result appendedSOC 2 CC7.5
Production deploy · model-card publishedISO 42001 A.6.2.5
Bias scan results chained per production modelISO 42001 A.10.3
Incident-response runbook drill loggedSOC 2 CC7.4

Data retention & the right to erasure

ERASURE VS. A TAMPER-EVIDENT LEDGER

Audit evidence is hash-chained and anchored into write-once storage (S3 Object Lock, compliance mode, ~7 years) — that immutability is the product. We reconcile this with GDPR erasure rights by design: personal data is redacted before it ever lands on the chain (automated PII redaction at the write boundary), so chained records describe events, not people. On a verified erasure request we (1) delete or de-identify personal data held in conventional storage, and (2) append a tombstone record to the ledger marking the subject's content as erased — the chain stays verifiable, the person's data is gone from every system that ever stored it in readable form.

Operational telemetry: deleted after 90 days (per-tenant configurable).
Marketing funnel identifiers: hashed at ingestion — plaintext email is not stored; aged identifiers age out at 90 days.
Reviewer-link snapshots: deleted after 180 days (never while a live reviewer link depends on one).
Ledger entries: never row-deleted; erasure handled by redaction-at-write + tombstones, as above.

Erasure requests: [email protected]. This describes our engineering posture; it is documentation, not legal advice.

Ask us about our security posture

Reference architecture, sub-processor list, DPA, our LLM data-handling posture, and a walkthrough of the ledger we run on ourselves. We'll tell you plainly what is and isn't certified.

Contact [email protected]Our posture in detail
Cognita GRC — The Cognitive Operating System for AI-Native Enterprises