Cognida.aiTrust Center
Automate by Cognida · Trust Center

Yourtrust,ourarchitecture!

Automate is an AI-powered execution layer for high-stakes finance and business operations — processing contracts, invoices, orders, and expenses against your accounting policies, then routing decisions into ERP and CRM systems.

This Trust Center documents how we protect your financial data at every stage.

0
Certifications
SOC 2, SOC 1, GDPR, CCPA
0+
Controls
All checks passing
0%
Uptime SLA
Measured annually
Apr '26
Last audit
Independent third-party

Compliance

Best-in-class compliance certifications

Credentials you can verify. To request a copy of any reports, reach out to Trust@cognida.ai

Security · Availability · Confidentiality

Within maintains SOC 2 Type II certification, audited annually by an independent third-party firm. Our SOC 2 report attests that Within's security controls meet the Trust Services Criteria across Security, Availability, and Confidentiality, covering the policies, procedures, and systems that protect customer data throughout our platform.

Financial reporting controls

Within maintains SOC 1 Type II certification, demonstrating that our internal controls relevant to customer financial reporting meet established standards. Our SOC 1 report is audited annually by an independent firm and is available on request.

EU data protection

Within is compliant with the General Data Protection Regulation (GDPR). We support customer rights under GDPR including access, rectification, erasure, and data portability and operate under a Data Processing Agreement (DPA) that governs how we handle personal data on behalf of our customers.

California privacy

Within complies with the California Consumer Privacy Act (CCPA). We do not sell personal data, and we provide customers and their end-users with the ability to request access, deletion, and disclosure of personal information we hold.

Controls

Updated 7 days ago
  • Encryption key access restricted
  • Unique account authentication enforced
  • Access control procedures established
  • Asset disposal procedures utilized
  • Portable media encrypted
  • Anti-malware technology utilized
  • Data encryption utilized
  • Control self-assessments conducted
  • Vulnerability and system monitoring procedures established
  • Continuity and Disaster Recovery plans established
  • Continuity and Disaster Recovery plans tested
  • Cybersecurity insurance maintained
  • Data retention procedures established
  • Customer data deleted upon leaving
  • Data classification policy established

Documents

Reports

SOC 1 Type II Report (Period: 2025-05-01 to 2025-10-31)

SOC 1 Type II Report

SOC 2 Type II Report (Period: 2025-05-01 to 2025-10-31)

SOC 2 Type II Report

Automate SOC 2 Type II Report (Period: 2025-11-01 to 2026-04-30)

Automate SOC 2 Type II Report

Policies

Information Security Policies and Procedures (2026-2027)

Information Security Policies and Procedures

GDPR Compliance Statement

GDPR Compliance Statement

Other documents

Automate AppSec Pentest Report.pdf

Automate AppSec Pentest Report

Architect 4.0 AppSec Pentest Report.pdf

Architect 4.0 AppSec Pentest Report

Within Product Packet 2026.pdf

Architect specific Policy Packet

Data collected

Customer personally identifiable information
Sensitive Personal Data

FAQ

All data is stored within secure data centers in the United States using Amazon Web Services (AWS).

Yes. The company uses private cloud deployments on both AWS and Google Cloud Platform (GCP) to provide each customer with a dedicated, secure environment.

No. Each customer's data resides in a separate, isolated environment to maintain strict data segregation.