Trust starts with traceability
SOC 2 Type II
Every fact Cotiss surfaces links back to the document it came from, so trust does not rest on taking our word for it.
Compliance
Cotiss is SOC 2 Type II certified. The full report is available on request, arranged through the demo process.
The same controls carry your side of it. The evidence a SOX 404(a) control needs, the artifacts your ISO 27001 audit asks for, and the trail a regulator expects to find are all produced as Cotiss runs, rather than assembled when someone asks.
What Cotiss reads is your call
What Cotiss reads, retains, exposes, and acts on is governed by the customer's own permissions and rules, set at onboarding and adjustable afterward. Most customers start narrow, granting access to a single vendor category or document type, and widen the scope as the picture proves itself out. Nothing is read outside what has been explicitly authorized.
Access controls
Access is set at the level each team and role needs, and no wider. A person or agent only reaches the vendors, contracts, and categories their role covers. Permissions are set by the customer, not assumed by default.
Data residency
Data is held in the region that matches where your company operates. We confirm residency requirements before onboarding, not after the fact.
Per-customer encryption keys
Each customer's data is encrypted with its own key, never shared with another customer's data or infrastructure. One customer's key cannot unlock another's records.
Encryption
Everything is encrypted in transit and at rest. Stored data uses AES-256-GCM, and the keys rotate.
Tenant isolation
Every query is filtered by organization at the row, so one customer's records are never in another customer's result set.
Audit trail
Every fact Cotiss surfaces carries a record of the document, line, or conversation it came from, and when it was read. The trail is available for review at any time, not reconstructed on request.
Where we start
Your business knows more than you can see.Give it a memory that acts.
Runs alongside your existing stack · Usage-based pricing