Cohesio
Security

What's actually true about security today

We'd rather tell you what isn't finished than make a claim we can't back up. This page will be updated as controls are implemented and verified — not before.

Planned controls

What the workspace must enforce before beta

These are design and release requirements, not claims about a production system. Cohesio will not accept real client data until they are implemented and verified.

Quarantine & malware scan

Uploaded files must be quarantined and scanned before conversion or review so no unchecked file reaches a reviewer.

Client & engagement isolation

A client's external access must be scoped to their own current engagement — never another client's records, and never a firm-wide login.

Role-based staff access

Internal staff roles must determine who can invite clients, review evidence, accept or waive requirements, and export a handoff.

Audit trail on consequential actions

Accept, correction request, waiver and completion actions must record who acted, when, and why — not just that something changed.

Deliberately excluded

Data Cohesio is not designed to collect or store

Phase 1 scope explicitly excludes sensitive categories that don't belong in a document-collection workspace.

  • Bank account passwords or online-banking credentials
  • Payment card security codes (CVV) or other stored card credentials
  • Medical or health records
  • KYC / identity-verification data
  • Payroll administration (wages, direct deposit setup, tax withholding)
Honest limitations

What is still in progress, not yet true

No certifications held

Cohesio does not currently hold SOC 2, ISO 27001, or any other independent security certification, and does not claim bank-grade or zero-retention handling anywhere on this site.

Incident response is being built

Formal incident-response runbooks, breach-notification processes and data-processing terms are being written and must be completed before any real client data is accepted.

Retention & backup policy in review

A specific, published retention and backup policy is still being finalized. It will describe exactly how long data is kept and how deletion actually works.

At cancellation

What happens to your data if you leave

The proposed service-end policy stops new external intake, AI processing and business messages, then gives an owner or admin a 30-day export window. This policy remains subject to operational and legal review.

Questions about our security posture?

Ask us directly — we'd rather answer a hard question now than have it surface after you've signed up.