Interim pilot policy. This general policy is pending legal review and may be replaced by executed customer terms. It is not legal advice.

Legal

Compliance Status

A transparent interim statement of Cominent’s present control posture and outstanding assurance work.

Effective August 9, 2026 · Last updated August 9, 2026 · Version 0.2 (interim)

01

Current status

Cominent is not currently represented as SOC 2 certified, SOC 2 examined, ISO/IEC 27001 certified, PCI DSS certified, HIPAA compliant, or independently penetration tested unless a current written report expressly says otherwise. Product controls can support a compliance program, but software features alone do not establish certification or legal compliance.

02

Technical controls implemented

  • Tenant-scoped authorization, role checks, record-level access, and minimized API responses.
  • Secure sessions, password hashing, SSO foundations, encrypted integration credentials, private storage, audit events, structured logs, and health monitoring.
  • Security headers, production CORS restrictions, request integrity controls, safe errors, data validation, and human approval for material AI actions.

03

SOC 2 readiness work still required

  • Define the system boundary and applicable Trust Services Criteria.
  • Approve policies, assign owners, conduct risk assessment, and operate controls for an evidence period.
  • Complete access reviews, vendor management, incident exercises, backup restoration tests, change-management evidence, vulnerability management, and security training.
  • Engage an independent CPA firm for a SOC 2 Type I or Type II examination. Only the resulting report can support an examination claim.

04

ISO/IEC 27001 readiness work still required

  • Establish an information security management system, scope, interested parties, risk methodology, risk register, treatment plan, and Statement of Applicability.
  • Operate and measure selected controls, complete internal audit and management review, correct nonconformities, and engage an accredited certification body.
  • Do not use ISO certification wording or marks until certification is formally issued.

05

Privacy program work still required

  • Confirm legal entity, privacy contact, processing roles, records of processing, retention schedule, deletion workflow, data-subject request procedure, DPIA process, and breach-notification procedure.
  • Execute a Data Processing Addendum where required; publish a subprocessor register and international-transfer mechanism before general availability.
  • Map applicable Canadian, provincial, EEA/UK, and US state requirements with qualified counsel.

06

Operational assurance backlog

  • Independent penetration test and remediation verification.
  • Centralized alerting with on-call ownership and incident severity/runbook definitions.
  • Documented backup restoration results, disaster-recovery exercises, recovery objectives, and business-continuity plan.
  • Software dependency and secret scanning in CI, asset inventory, patch SLAs, secure SDLC evidence, and periodic access certification.
  • Cyber insurance, employee/contractor confidentiality controls, background screening where lawful, and vendor security reviews.

07

Customer diligence

Pilot customers should evaluate the service against their own data classification, regulatory duties, contractual requirements, and risk tolerance. Current evidence should be requested directly; this page is informational and is not an audit report, attestation, certification, warranty, or legal opinion.

Questions about these interim policies should be directed to your designated Cominent pilot contact.