Security and data handling

How Cogna8 treats your data and its own actions.

Principles

PrincipleIn practice
Least privilegeConnectors read only what they need; agents get only the tools they are granted
Append-only recordsHistory and receipts are never edited or deleted
IsolationScopes keep one case, client or conversation from seeing another
Content minimisationUsage telemetry is ingested with prompt and personal content stripped
Humans decideThe copilot and the gate never apply changes or approvals without a person where policy requires it

Your responsibilities

  1. 1
    Protect API keys

    Store them in a secrets manager and rotate on suspicion.

  2. 2
    Fail closed

    Agents must not act if the gate cannot be reached.

  3. 3
    Review access

    Remove unused tool grants and keep owners current.

For security questions or to report a vulnerability, contact us. Our privacy policy is at cogna8.ai/policy.

Last reviewed October 2026Suggest a change