Security

Drawings never stored outside of your environment.

How Cognaize Systems handles customer drawings and project data — deployed on-premise or in your private cloud, processed in memory, and certified to ISO/IEC 27001.

Runs in your environment

Deploy on-premise or in your own private cloud. The application runs as containerized services behind your existing IT controls — drawings, project files, and analysis records are never stored outside your environment.

In-memory AI only

Content sent for AI analysis is processed in memory and discarded — never written to disk, never logged. There is no Cognaize-hosted store of your data.

You stay in control

Access, backup, retention, and deletion of drawings and outputs remain fully under your control. Cognaize Systems staff have no remote access to your deployment.

No inbound connectionsNo remote access by Cognaize SystemsOne outbound endpoint — ai.cognaizesys.com (HTTPS 443)In-memory processing — never storedTLS 1.2+ on every hopAES-256 at rest
Penetration Testing

Independently Tested

Design Intelligence and Manufacturing Intelligence have each undergone Vulnerability Assessment and Penetration Testing (VAPT), earning an “Excellent” security level.

A is the highest grade on the assessment scale.

A

Design Intelligence (DI)

Excellent — exceeds industry best practice

VAPT · Scope: Web application

A

Manufacturing Intelligence (MI)

Excellent — exceeds industry best practice

VAPT · Scope: Web application

Security Controls

Controls We Operate

Beyond the product architecture, we run standard organisational security controls across the business.

Access Control & Identity

  • Role-based, least-privilege access
  • MFA on admin and cloud accounts
  • Periodic access reviews

Secure Development

  • Peer code review before merge
  • Dependency & supply-chain scanning
  • Secrets kept out of source code

Logging & Monitoring

  • Centralised system & access logs
  • Continuous monitoring with alerting
  • Audit trails retained for review

Data Protection & Encryption

  • TLS 1.2+ in transit; AES-256 at rest
  • Keys held in a managed key-management service
  • Data minimisation & classification

Risk, Policy & Awareness

  • Security policies & risk assessments
  • Staff security-awareness training
  • Acceptable-use & device undertakings

Resilience & Response

  • Incident response & escalation process
  • Business continuity & DR planning
  • Backups with tested restoration
Certifications

Independently Certified

Need the certificate for a vendor assessment, RFP, or audit? Tell us who you are and we'll email you a download link right away.

ISO/IEC 27001 certification mark

ISO/IEC 27001

Certified

Information Security Management

Our information security management system is certified to ISO/IEC 27001 — covering how we protect the drawings, production data, and customer information our products handle.

Certified by TÜV SÜD · verifiable at tuvsud.com/ms-cert

The cloud and AI platforms our products run on maintain their own major third-party security certifications, including SOC, the ISO 27000 family, and FedRAMP.