Legal · Security overview

Security starts with reducing what the product is allowed to do.

Cognia is designed around read-only asset visibility, clear custody boundaries, protected data, controlled operations, and evidence that can be reviewed without exposing transaction authority.

Private keys requestedNever
Asset connectionsRead-only
Protection modelLayered

A shared responsibility model

Cognia protects the infrastructure and product capabilities under its control. Users and organizations remain responsible for their devices, identities, account administration, source permissions, secure configuration, and decisions about what data to connect or upload.

This overview describes design principles rather than a guarantee that incidents can never occur. Enterprise security documentation and contractual commitments may provide additional detail for approved due-diligence processes.

01

Custody and connection boundaries

Cognia is designed to observe and organize asset data, not to take custody or sign transactions. Public wallet addresses and read-only exchange connections reduce the authority exposed to the product.

  • Cognia does not ask for wallet seed phrases or private keys.
  • Exchange API credentials should exclude trading, withdrawal, and transfer permissions.
  • Users should verify permissions at the source and rotate credentials after suspected exposure.
02

Data protection and access

Cognia applies technical and organizational measures intended to protect data through its lifecycle, including controls for transmission, storage, access, and operational handling.

  • Encryption in transit and at rest for supported systems.
  • Access controls and least-privilege operating practices.
  • Logging, monitoring, backup, and recovery practices appropriate to the service.
  • Provider and dependency review proportionate to the data and function involved.
03

Secure product and operations

Security is considered across design, development, release, and incident response. Controls evolve with the product, threat environment, and customer requirements.

  • Code review, dependency management, and testing before release.
  • Separation of environments and controlled production access.
  • Monitoring and triage for suspicious or unexpected behavior.
  • Incident response procedures, investigation, containment, recovery, and notification where required.
04

Customer security checklist

Users can materially reduce risk by keeping permissions narrow and responding quickly to unexpected activity.

  • Enable strong authentication and protect recovery channels.
  • Use dedicated read-only API credentials where possible.
  • Review connected sources and authorized users regularly.
  • Never send secrets, raw credentials, or private keys through support email or chat.
05

Report a security concern

Send a concise report to [email protected] with the subject 'Security report'. Include the affected URL or feature, reproduction steps, impact, and a safe way to contact you. Do not access other users' data, disrupt the service, use social engineering, or publish an unresolved issue before the team has a reasonable opportunity to respond.

Do not include live credentials, private keys, seed phrases, or unnecessary personal or portfolio data in the initial report.

Found something that could make Cognia safer?

Report it responsibly with enough detail for the team to reproduce and assess the issue.