Security and data handling
How Cogna8 treats your data and its own actions.
Principles
| Principle | In practice |
|---|---|
| Least privilege | Connectors read only what they need; agents get only the tools they are granted |
| Append-only records | History and receipts are never edited or deleted |
| Isolation | Scopes keep one case, client or conversation from seeing another |
| Content minimisation | Usage telemetry is ingested with prompt and personal content stripped |
| Humans decide | The copilot and the gate never apply changes or approvals without a person where policy requires it |
Your responsibilities
- 1Protect API keys
Store them in a secrets manager and rotate on suspicion.
- 2Fail closed
Agents must not act if the gate cannot be reached.
- 3Review access
Remove unused tool grants and keep owners current.
For security questions or to report a vulnerability, contact us. Our privacy policy is at cogna8.ai/policy.
Last reviewed October 2026Suggest a change