SOP · Partners · The Cognition Factory
Security & Compliance SOP
High-level security and compliance posture for HAL-E and AAE — written for prospective clients, partners, and decision-makers in evaluation and sales discussions.
1. Purpose
Give decision-makers a clear picture of posture without turning a brochure into an attack surface.
2. Scope
Applies to enterprise and institutional deployments of HAL-E and AAE. Summarizes key controls and compliance considerations at evaluation depth.
3. Compliance frameworks
GDPR
Personal data processed in accordance with GDPR principles. Processing limited to what service delivery requires. Users retain rights of access, rectification, erasure, and portability. Data Processing Agreements (DPAs) available for enterprise customers on request.
ISO 27001 alignment
Information security management practices aligned with ISO 27001 principles: access control, incident management, risk assessment, and continuous improvement of controls.
4. Data handling principles
- Data minimization — only necessary data collected and retained
- Purpose limitation — use limited to agreed purposes
- Security by design — privacy and security embedded in architecture
- Transparency — customers informed what is processed and why
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest with industry-standard algorithms
- Role-based access controls and audit logging
- Regular security assessments and vulnerability management
- Secure development practices and code review
- Incident response procedures with defined escalation paths
6. Roles and responsibilities
Shared model: The Cognition Factory is responsible for platform security; customers configure access appropriately, manage organizational accounts, and ensure lawful use in their jurisdiction and industry.
7. Subprocessors and third parties
A limited set of subprocessors (for example infrastructure providers) supports delivery. Current lists are available to enterprise customers on request. Subprocessors are contractually bound to confidentiality and security obligations.
8. Incident response
Documented procedures. On a confirmed incident affecting customer data, affected customers are notified without undue delay, per law and contract.
9. Deeper documentation
Technical controls, risk assessments, and operational procedures are available to qualified prospects and customers under appropriate confidentiality agreements.