Legal
Security & Data Protection
An interim overview of Cominent’s security approach during private pilot.
Effective August 9, 2026 · Last updated August 9, 2026 · Version 0.2 (interim)
01
Security approach
- Tenant-aware authorization and role-based access controls.
- Encrypted transport and protected credential handling.
- Hashed server-side sessions, short-lived authentication transactions, and secure OAuth flows.
- Audit and security event records for sensitive activity.
- Least-privilege integration scopes and provider permission enforcement.
- Human confirmation for material AI-proposed actions.
02
Controls currently implemented in the application
- Organization-scoped authorization and repository queries for protected business records.
- HTTP-only, Secure production session cookies; hashed server-side session tokens; expiration, revocation, and sign-out controls.
- Password hashing with salted scrypt, login throttling, temporary lockout, and generic authentication errors.
- OAuth state protection, replay resistance, encrypted connector credentials, and environment-managed secrets.
- Private object storage architecture with tenant-scoped keys and application-authorized downloads.
- Request identifiers, structured security logs, health/readiness endpoints, input schemas, size limits, and safe production error responses.
- HSTS, content security policy, anti-framing, no-sniff, restrictive permissions policy, referrer controls, CORS allowlisting, cache prevention for private APIs, and request-integrity checks for session mutations.
- Human review boundaries for AI-proposed operational records and explicit tenant context for assistant and connector execution.
03
Identity and access management
Cominent is designed to support organization-scoped membership, role-based permissions, project and relationship access, managed SSO, session expiration, session revocation, and recovery controls. Organizations must validate roles and remove access promptly when responsibilities change.
04
Data protection
Data is intended to be encrypted in transit and protected at rest using managed infrastructure controls. Secrets and provider tokens should be encrypted or otherwise protected, isolated from ordinary application output, and limited to the minimum authorized scopes. Production configuration and contractual commitments remain subject to validation.
05
Application and infrastructure security
- Secure development review and dependency maintenance.
- Input validation and deny-by-default authorization at protected boundaries.
- Environment separation and restricted production access.
- Logging and monitoring designed to avoid exposing credentials or private content.
- Backups, recovery procedures, and change controls appropriate to service maturity.
06
AI and connector safeguards
Connected sources remain subject to tenant, user, record, and provider permissions. Retrieved information should carry source context and citations where available. Automation proposals must not silently become material commitments, approvals, agreements, or external actions without required authorization and confirmation.
07
Security monitoring and incident response
Cominent maintains processes intended to identify, assess, contain, remediate, and learn from security events. Confirmed incidents will be prioritized based on scope and risk. Formal notification timelines, forensic support, and customer cooperation obligations must be defined in executed enterprise terms.
08
Business continuity and recovery
The service is designed to use backups and recovery procedures appropriate to its maturity. Recovery time, recovery point, availability, and disaster-recovery commitments are not guaranteed by this interim overview and require a production service agreement.
09
Personnel and service providers
Access to production systems and customer information should be limited to authorized personnel and providers with a business need, appropriate confidentiality duties, and proportionate controls. A formal subprocessor list and data-processing terms should be published before general production availability.
10
Shared responsibility
Organizations are responsible for configuring access, selecting appropriate integrations, managing members, reviewing AI output, and promptly reporting suspected compromise. Security capabilities evolve during pilot and should be evaluated against your organization’s requirements before sensitive production use.
11
Security limitations
No platform can promise that it will never be breached. This overview describes intended controls and does not constitute a certification, warranty, penetration-test report, or guarantee. Customers should perform their own risk assessment and request current evidence before production deployment.
12
Reporting concerns
Please report suspected security or privacy issues through your designated Cominent pilot contact. Do not perform intrusive testing without prior written authorization.
