Security at Syncora

1. Encryption

AES-256 at rest, TLS 1.3 in transit.

2. Access Controls

Role-based access, SSO, MFA.

3. Audit Logging

Reasoning Trace + AIDecision + ConsentRecord audit logs.

4. Sub-Processors

View public sub-processor list →

5. Penetration Testing

Not yet done. We have scoped an annual external penetration test and shortlisted testing firms. No test has been run, so there is no report to share.

6. SOC 2

Scoped, not yet audited. We have mapped the Trust Services Criteria and plan a Type 1 report first, then a Type 2. We have not engaged an auditor and the Type 2 observation period is not set. No SOC 2 report exists today, and we will not quote a date we cannot support.

7. ISO 27001 + ISO 42001

Neither is certified. ISO 27001 is scoped. ISO 42001 (AI Management System) work has not started — the control set is loaded but no evidence is gathered. We hold no certificate for either.

8. Vulnerability Disclosure

security@cognitive-corp.com + safe harbor for ethical researchers.

9. Incident Response

Documented IR plan, multi-state breach notification template (10 jurisdictions seeded), BIPA-aware incident handling.

10. Compliance Atlas

Open Trust Center →

Last updated: June 2026.