Interim pilot policy. This general policy is pending legal review and may be replaced by executed customer terms. It is not legal advice.

Legal

Security & Data Protection

An interim overview of Cominent’s security approach during private pilot.

Effective August 9, 2026 · Last updated August 9, 2026 · Version 0.2 (interim)

01

Security approach

  • Tenant-aware authorization and role-based access controls.
  • Encrypted transport and protected credential handling.
  • Hashed server-side sessions, short-lived authentication transactions, and secure OAuth flows.
  • Audit and security event records for sensitive activity.
  • Least-privilege integration scopes and provider permission enforcement.
  • Human confirmation for material AI-proposed actions.

02

Controls currently implemented in the application

  • Organization-scoped authorization and repository queries for protected business records.
  • HTTP-only, Secure production session cookies; hashed server-side session tokens; expiration, revocation, and sign-out controls.
  • Password hashing with salted scrypt, login throttling, temporary lockout, and generic authentication errors.
  • OAuth state protection, replay resistance, encrypted connector credentials, and environment-managed secrets.
  • Private object storage architecture with tenant-scoped keys and application-authorized downloads.
  • Request identifiers, structured security logs, health/readiness endpoints, input schemas, size limits, and safe production error responses.
  • HSTS, content security policy, anti-framing, no-sniff, restrictive permissions policy, referrer controls, CORS allowlisting, cache prevention for private APIs, and request-integrity checks for session mutations.
  • Human review boundaries for AI-proposed operational records and explicit tenant context for assistant and connector execution.

03

Identity and access management

Cominent is designed to support organization-scoped membership, role-based permissions, project and relationship access, managed SSO, session expiration, session revocation, and recovery controls. Organizations must validate roles and remove access promptly when responsibilities change.

04

Data protection

Data is intended to be encrypted in transit and protected at rest using managed infrastructure controls. Secrets and provider tokens should be encrypted or otherwise protected, isolated from ordinary application output, and limited to the minimum authorized scopes. Production configuration and contractual commitments remain subject to validation.

05

Application and infrastructure security

  • Secure development review and dependency maintenance.
  • Input validation and deny-by-default authorization at protected boundaries.
  • Environment separation and restricted production access.
  • Logging and monitoring designed to avoid exposing credentials or private content.
  • Backups, recovery procedures, and change controls appropriate to service maturity.

06

AI and connector safeguards

Connected sources remain subject to tenant, user, record, and provider permissions. Retrieved information should carry source context and citations where available. Automation proposals must not silently become material commitments, approvals, agreements, or external actions without required authorization and confirmation.

07

Security monitoring and incident response

Cominent maintains processes intended to identify, assess, contain, remediate, and learn from security events. Confirmed incidents will be prioritized based on scope and risk. Formal notification timelines, forensic support, and customer cooperation obligations must be defined in executed enterprise terms.

08

Business continuity and recovery

The service is designed to use backups and recovery procedures appropriate to its maturity. Recovery time, recovery point, availability, and disaster-recovery commitments are not guaranteed by this interim overview and require a production service agreement.

09

Personnel and service providers

Access to production systems and customer information should be limited to authorized personnel and providers with a business need, appropriate confidentiality duties, and proportionate controls. A formal subprocessor list and data-processing terms should be published before general production availability.

10

Shared responsibility

Organizations are responsible for configuring access, selecting appropriate integrations, managing members, reviewing AI output, and promptly reporting suspected compromise. Security capabilities evolve during pilot and should be evaluated against your organization’s requirements before sensitive production use.

11

Security limitations

No platform can promise that it will never be breached. This overview describes intended controls and does not constitute a certification, warranty, penetration-test report, or guarantee. Customers should perform their own risk assessment and request current evidence before production deployment.

12

Reporting concerns

Please report suspected security or privacy issues through your designated Cominent pilot contact. Do not perform intrusive testing without prior written authorization.

Questions about these interim policies should be directed to your designated Cominent pilot contact.
Security & Data Protection — Cominent