Security starts with reducing what the product is allowed to do.
Cognia is designed around read-only asset visibility, clear custody boundaries, protected data, controlled operations, and evidence that can be reviewed without exposing transaction authority.
A shared responsibility model
Cognia protects the infrastructure and product capabilities under its control. Users and organizations remain responsible for their devices, identities, account administration, source permissions, secure configuration, and decisions about what data to connect or upload.
This overview describes design principles rather than a guarantee that incidents can never occur. Enterprise security documentation and contractual commitments may provide additional detail for approved due-diligence processes.
Custody and connection boundaries
Cognia is designed to observe and organize asset data, not to take custody or sign transactions. Public wallet addresses and read-only exchange connections reduce the authority exposed to the product.
- Cognia does not ask for wallet seed phrases or private keys.
- Exchange API credentials should exclude trading, withdrawal, and transfer permissions.
- Users should verify permissions at the source and rotate credentials after suspected exposure.
Data protection and access
Cognia applies technical and organizational measures intended to protect data through its lifecycle, including controls for transmission, storage, access, and operational handling.
- Encryption in transit and at rest for supported systems.
- Access controls and least-privilege operating practices.
- Logging, monitoring, backup, and recovery practices appropriate to the service.
- Provider and dependency review proportionate to the data and function involved.
Secure product and operations
Security is considered across design, development, release, and incident response. Controls evolve with the product, threat environment, and customer requirements.
- Code review, dependency management, and testing before release.
- Separation of environments and controlled production access.
- Monitoring and triage for suspicious or unexpected behavior.
- Incident response procedures, investigation, containment, recovery, and notification where required.
Customer security checklist
Users can materially reduce risk by keeping permissions narrow and responding quickly to unexpected activity.
- Enable strong authentication and protect recovery channels.
- Use dedicated read-only API credentials where possible.
- Review connected sources and authorized users regularly.
- Never send secrets, raw credentials, or private keys through support email or chat.
Report a security concern
Send a concise report to [email protected] with the subject 'Security report'. Include the affected URL or feature, reproduction steps, impact, and a safe way to contact you. Do not access other users' data, disrupt the service, use social engineering, or publish an unresolved issue before the team has a reasonable opportunity to respond.
Do not include live credentials, private keys, seed phrases, or unnecessary personal or portfolio data in the initial report.
Continue exploring
More from this part of Cognia, built around the same operating principles.
Privacy should remain visible wherever financial data moves.
This notice explains how Cognia may collect, use, disclose, retain, and protect personal data across this website, the Cognia product, support, and related business interactions.
Clear responsibilities for a product built around consequential decisions.
These terms govern access to the public Cognia website, product, documentation, outputs, and related services unless a signed order form or other agreement states different terms.
Understand the limits before acting on the output.
Cognia helps organize portfolio data and prepare analysis, scenarios, and evidence. It does not remove market risk, data risk, model risk, legal uncertainty, or the need for professional judgment.
Found something that could make Cognia safer?
Report it responsibly with enough detail for the team to reproduce and assess the issue.