Quarantine & malware scan
Uploaded files must be quarantined and scanned before conversion or review so no unchecked file reaches a reviewer.
We'd rather tell you what isn't finished than make a claim we can't back up. This page will be updated as controls are implemented and verified — not before.
These are design and release requirements, not claims about a production system. Cohesio will not accept real client data until they are implemented and verified.
Uploaded files must be quarantined and scanned before conversion or review so no unchecked file reaches a reviewer.
A client's external access must be scoped to their own current engagement — never another client's records, and never a firm-wide login.
Internal staff roles must determine who can invite clients, review evidence, accept or waive requirements, and export a handoff.
Accept, correction request, waiver and completion actions must record who acted, when, and why — not just that something changed.
Phase 1 scope explicitly excludes sensitive categories that don't belong in a document-collection workspace.
Cohesio does not currently hold SOC 2, ISO 27001, or any other independent security certification, and does not claim bank-grade or zero-retention handling anywhere on this site.
Formal incident-response runbooks, breach-notification processes and data-processing terms are being written and must be completed before any real client data is accepted.
A specific, published retention and backup policy is still being finalized. It will describe exactly how long data is kept and how deletion actually works.
The proposed service-end policy stops new external intake, AI processing and business messages, then gives an owner or admin a 30-day export window. This policy remains subject to operational and legal review.
Ask us directly — we'd rather answer a hard question now than have it surface after you've signed up.