Security posture.
How assessment data is handled, how evidence is signed, and who can touch it. Subprocessors and the data processing agreement are linked at the foot of this page.
Encryption
Data is encrypted in transit and at rest. Keys are scoped per environment and rotated on a fixed schedule.
Evidence integrity
Score responses use documented judgment envelopes and audit-chain records. Signed per-decision receipts are issued from the DRS gate path and can be verified after issuance.
Access control
Least privilege access with audit logging. No standing access to customer assessment data.
Data minimization
Only the telemetry needed to score a window is processed. JIS telemetry is treated as personal data.
Deployment options
Hosted, private cloud, or self hosted. Enterprise can keep all data inside its own environment.
Retention
Retention windows are bounded by the data processing agreement and configurable for enterprise deployments.
Need a security review before procurement?
For responsible disclosure and vulnerability reports, email security@cohesionauth.com.