Skip to content
Cogio

Trust centre

Sovereignty is not a sales pitch, it is our architecture

This page sets out, without superlatives, how we protect the data entrusted to us: our pillars, our practices, our measurable commitments, and the things we never do.

Last updated: July 16, 2026

Four pillars, no exceptions

Your data stays with you

Our AI agents are deployed on your infrastructure or on Canadian servers you control. Your documents do not pass through public AI services.

No training on your data

Never. Your documents are used to answer your questions, not to improve a model, ours or anyone else’s.

A human keeps control

The AI prepares, proposes and flags; a person approves. No agent we deploy sends anything or decides anything without human supervision.

Encryption and partitioning

Encrypted communications (TLS 1.2 and above), data encrypted at rest, role-based access limited to the people who need it, and access logging.

Compliance and reference frameworks

We draw a line between what we comply with and what we align ourselves to. The statuses below are accurate as of the date this page was last updated.

Law 25 (Quebec)

Compliant

A privacy officer is appointed, an incident register is maintained, and a privacy impact assessment (PIA) is built into every engagement that touches personal information.

Our Law 25 guide →

PIPEDA (Canada)

Compliant

Our practices meet the federal privacy legislation that applies to commercial activities.

Privacy policy →

ISO 27001

Practices aligned

Our security practices are modelled on the ISO 27001 standard, with no certification to date. We would rather say so plainly: a badge does not protect data, practices do.

ISO 27001 explained →

SOC 2

Criteria applied

We apply the SOC 2 security and confidentiality criteria as a yardstick for our suppliers and for our own systems, with no formal audit to date.

SOC 2 explained →

Our practices, in detail

Sovereign hosting
  • Deployment preferably on the client’s own infrastructure, on site or in a Canadian data centre they control.
  • No mandatory dependency on a cloud provider subject to the US CLOUD Act for sensitive data.
  • Open AI models running locally: queries never leave the client’s environment.
  • Transfers outside Quebec, when they are unavoidable, are preceded by a privacy impact assessment under section 17 of Law 25.
Access control
  • Access granted on the principle of least privilege, by role.
  • Multi-factor authentication required on our internal systems.
  • Access to client environments is named, logged and revoked as soon as the engagement ends.
  • Periodic review of access rights and permissions.
Data protection
  • Encryption of communications (TLS 1.2 and above) and of data at rest.
  • Strict partitioning between each client’s environments.
  • No copy of client data kept beyond what the services agreement provides for.
  • Secure destruction or return of data at the end of the engagement, with an attestation on request.
Development and deployment
  • Code review before anything goes into production at a client site.
  • Test environments fed with anonymized or synthetic data wherever possible.
  • A change log kept for every deployment.
  • Security updates applied promptly to the components we manage.
Supplier management
  • Subcontractors bound by confidentiality and personal information protection undertakings.
  • A standing preference for Canadian suppliers, or suppliers that host in Canada.
  • A list of subcontractors available on request.
  • Suppliers reassessed whenever their practices change significantly.
Continuity and incidents
  • Encrypted, verified backups of our internal systems.
  • A documented incident response procedure: contain, assess, notify, correct, record.
  • Prompt notification of the Commission d’accès à l’information and of the people concerned in the event of an incident presenting a risk of serious injury, as Law 25 requires.
  • A register of confidentiality incidents kept up to date.

Commitments that can be measured

48 hours

to answer a security report, on business days

30 days

maximum time to answer an access or deletion request

100%

of engagements touching personal information documented by a privacy impact assessment

0

pieces of client data ever used to train a model, since day one

Documents available on request

We are a firm, not a platform: rather than a document portal, an email will do. Write to support@cogio.ai to get:

  • Verifiable client references (role and industry), on request and with each client’s agreement
  • Information security policy
  • Privacy impact assessment (PIA) template
  • List of subcontractors and where they are located
  • Incident response procedure
  • Attestation of data destruction or return (end of engagement)

Frequently asked security questions

Where is my data hosted during an engagement?

On your own infrastructure, or on Canadian servers you control, depending on the architecture we settle on together during scoping. Our starting principle: your documents do not leave your environment. When a component has to be hosted elsewhere, it is spelled out in black and white in the agreement and preceded by a privacy impact assessment.

Do you use my data to train AI models?

No, never. The agents we deploy read your documents in order to answer, an approach known as RAG, without retraining any model. No client data is ever used to improve a model, ours or a supplier’s.

How does Cogio comply with Law 25?

A privacy officer is appointed, every engagement touching personal information goes through a privacy impact assessment, incidents are entered in a register and reported to the Commission d’accès à l’information when required, and our agreements govern confidentiality and data destruction. Our privacy policy sets all of it out.

Who has access to my data during an engagement?

Only the team members assigned to your engagement, through named and logged accounts that are revoked as soon as the work ends. No account is shared, and no third party gets access without your written consent.

What happens in the event of a security incident?

We follow our response procedure: contain the incident, assess the risk of injury, notify you without delay, fix the cause and record everything in the register. If the incident presents a risk of serious injury, the Commission d’accès à l’information and the people concerned are notified promptly, as Law 25 requires.

How do I report a vulnerability?

Write to us at support@cogio.ai with a description of the problem and the steps to reproduce it. We acknowledge receipt within 48 hours on business days, and we take no legal action against good-faith researchers.

A question this page does not cover?

Write to us: the person who replies is the one who designs the architectures.

support@cogio.ai