Devin (Cognition)'s trust-center changed
Cognition Trust Center Start your security review View & download sensitive information Ask for information Welcome to Cognition's Trust Center. We want Devin to be a core contributor to your codebase, and have prioritized security, data privacy and compliance to make it possible. Use this Trust Center to learn about our security posture and request access to our security documentation. Accessing the documentation on our Trust Center: Please request access via the banner above. You will be sent an invite via email, and will be prompted to sign an NDA once in the portal. Once the NDA is signed, you will have access to view and download the resources in our Trust Center. CCPA SOC 2 Type 2 ISO/IEC 27001:2022
ADDEDDOCUMENTS Finance
REPORTS Network Diagram REPORTS Pentest Report REPORTS SOC 2 Report REPORTS SOC 2 Type 2 Bridge Letter COMPLIANCE ISO/IEC 27001:2022 COMPLIANCE SOC 2 Type 2 LEGAL Certificate of Insurance LEGAL W-9
ADDEDData Access Level Internal Impact Level Substantial Recovery Time Objective 48 hours View more
Data Access Level Internal Impact Level Substantial Recovery Time Objective 48 hours View more We pay great attention to enterprise features such as access control and single sign on. We are happy to provide more details about our enterprise features upon request.
REMOVEDPentest Report
ADDEDSOC 2 Type 2 Bridge Letter Pentest Report SOC 2 Report View more
SOC 2 Type 2 Bridge Letter
ADDEDPentest Report
SOC 2 Report We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request. We take application security seriously and are putting together a program to monitor internal apps.
ADDEDData Processing Addendum Certificate of Insurance Privacy Policy View more
Data Processing Addendum Certificate of Insurance Privacy Policy Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations. Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request. We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request. We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request. We protect our corporate network against external & internal threats. We implement internal measures and practices to maintain a high standard of security. Acceptable Use Policy We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request. We have strict asset management policies in place to ensure that all assets are accounted for and secure. We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster. We provide security awareness training to all employees to ensure that they are aware of security best practices. We have a change and configuration management process in place to ensure that changes are properly reviewed and approved. We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.
ADDEDAudit and Monitoring - How is the data you store encrypted in transit? Business Continuity and Disaster Recovery - Does the company have a Business Continuity Plan (BCP) that meets recovery objectives? Third-Party Audits and Certifications - Have you undergone any security audits or obtained relevant certifications? Secure Software Development - Is there a bug bounty program in place? Business Continuity and Disaster Recovery - How often is the disaster recovery plan tested?
Audit and Monitoring - How is the data you store encrypted in transit? Business Continuity and Disaster Recovery - Does the company have a Business Continuity Plan (BCP) that meets recovery objectives? Third-Party Audits and Certifications - Have you undergone any security audits or obtained relevant certifications? Secure Software Development - Is there a bug bounty program in place? Business Continuity and Disaster Recovery - How often is the disaster recovery plan tested?