Procurement artefacts, on request.
Everything your security, compliance, and legal teams typically ask for during due diligence — SOC 2 Type II, DPA, BAA, subprocessor list, incident response summary, penetration test letter. We ship each artefact under NDA within one business day of request.
SOC 2 Type II Report
AvailableFull report from our independent auditor covering the Security, Availability, and Confidentiality trust service criteria. Delivered under mutual NDA within 1 business day of request.
Request under NDA →Data Processing Agreement (DPA)
AvailableGDPR-aligned DPA template including the EU Standard Contractual Clauses, processing purposes, technical & organizational measures, and the current subprocessor list.
Request under NDA →Business Associate Agreement (BAA)
Enterprise planHIPAA-aligned BAA template for healthcare-education institutions on the Enterprise plan. Includes safeguard obligations, breach notification windows, and permitted uses.
Request under NDA →Subprocessor List
AvailableCurrent list of our third-party subprocessors, their location, and the category of data they process. Updated whenever we add or remove a vendor; subscribe to get notified.
Request under NDA →Security Whitepaper
AvailableArchitectural overview of how Cognaxa enforces tenant isolation at the PostgreSQL query planner, how the AI proctoring engine is isolated, and how we handle secrets, keys, and audit logs.
Request under NDA →Incident Response Summary
AvailableOne-page summary of our incident response plan — detection, triage, communication, post-mortem. The full runbook is shared during procurement due-diligence.
Request under NDA →Penetration Test Letter
AnnualSummary letter from our annual third-party penetration test. Includes scope, methodology, and a remediation status statement.
Request under NDA →ISO 27001 Statement of Applicability
InterimCurrent Statement of Applicability against the ISO 27001 controls set. Formal certification is in progress — targeted Q4 2026.
Request under NDA →How we deliver these
A simple, fast process for getting the documents your security review needs.
- 01You request
Use the "Request under NDA" button above. Tell us which artefact you need and who will review it.
- 02Mutual NDA
We counter-sign your NDA template or send ours. Typical turnaround is under 4 business hours.
- 03Secure delivery
The artefact ships via a time-limited, access-logged link. Copies are never emailed as plain attachments.
- 04Q&A
Our security team is available for follow-up questions, architecture walkthroughs, and custom security questionnaires.
Security questions not in the list?
Our security team handles custom questionnaires, architecture reviews, and ad-hoc requests directly.
security@genfinish.com →