Legal
Security policy
High-level security practices for Cogrova customer workspaces on cogrova.com.
Draft / placeholder overview. Not a penetration-test report or SOC 2 certificate. Ask for a security questionnaire via Contact for due diligence.
Access control
Workspaces are separated by account. Owners and admins manage invitations and roles. Use strong passwords and protect account credentials.
Encryption & transport
Traffic to the service is protected with HTTPS/TLS. Sensitive secrets are stored using appropriate server-side protections.
Infrastructure
We host on reputable cloud infrastructure. Operational access to production systems is limited to authorized personnel.
Monitoring & incidents
We monitor for abuse and outages. If a security incident affecting your workspace is confirmed, we will notify affected customers as required and practical.
Your responsibilities
You are responsible for the content you upload, who you invite, and configuring permissions appropriately. Report suspected compromise immediately via Contact.