Trust / Downloads

Procurement artefacts, on request.

Everything your security, compliance, and legal teams typically ask for during due diligence — SOC 2 Type II, DPA, BAA, subprocessor list, incident response summary, penetration test letter. We ship each artefact under NDA within one business day of request.

SOC 2 Type II Report

Available
For: Security & Compliance

Full report from our independent auditor covering the Security, Availability, and Confidentiality trust service criteria. Delivered under mutual NDA within 1 business day of request.

Request under NDA →

Data Processing Agreement (DPA)

Available
For: Legal & Procurement

GDPR-aligned DPA template including the EU Standard Contractual Clauses, processing purposes, technical & organizational measures, and the current subprocessor list.

Request under NDA →

Business Associate Agreement (BAA)

Enterprise plan
For: Healthcare & Regulated Industries

HIPAA-aligned BAA template for healthcare-education institutions on the Enterprise plan. Includes safeguard obligations, breach notification windows, and permitted uses.

Request under NDA →

Subprocessor List

Available
For: Privacy & Compliance

Current list of our third-party subprocessors, their location, and the category of data they process. Updated whenever we add or remove a vendor; subscribe to get notified.

Request under NDA →

Security Whitepaper

Available
For: Engineering & Security

Architectural overview of how Cognaxa enforces tenant isolation at the PostgreSQL query planner, how the AI proctoring engine is isolated, and how we handle secrets, keys, and audit logs.

Request under NDA →

Incident Response Summary

Available
For: Security & Risk

One-page summary of our incident response plan — detection, triage, communication, post-mortem. The full runbook is shared during procurement due-diligence.

Request under NDA →

Penetration Test Letter

Annual
For: Security

Summary letter from our annual third-party penetration test. Includes scope, methodology, and a remediation status statement.

Request under NDA →

ISO 27001 Statement of Applicability

Interim
For: Compliance

Current Statement of Applicability against the ISO 27001 controls set. Formal certification is in progress — targeted Q4 2026.

Request under NDA →
How it works

How we deliver these

A simple, fast process for getting the documents your security review needs.

  1. 01
    You request

    Use the "Request under NDA" button above. Tell us which artefact you need and who will review it.

  2. 02
    Mutual NDA

    We counter-sign your NDA template or send ours. Typical turnaround is under 4 business hours.

  3. 03
    Secure delivery

    The artefact ships via a time-limited, access-logged link. Copies are never emailed as plain attachments.

  4. 04
    Q&A

    Our security team is available for follow-up questions, architecture walkthroughs, and custom security questionnaires.

Security questions not in the list?

Our security team handles custom questionnaires, architecture reviews, and ad-hoc requests directly.

security@genfinish.com →