Security & trust

Secure by architecture.

Cohesor sits on the hot path of your most sensitive traffic — so it's built to hold the least, encrypt the rest, and prove every request. No training on your data, ever.

Keys, handled right

Provider keys are encrypted at rest and never returned to the browser. Gateway keys are shown once and stored only as a SHA-256 hash.

🔐

Client-side OAuth

MCP OAuth tokens stay on the client. Cohesor brokers tool calls without warehousing your third-party credentials.

Tenant isolation

Every workspace is isolated — keys, budgets, caches and audit logs never cross tenant boundaries.

Policy before egress

PII redaction, prompt-injection scanning and data-residency pinning run in-gateway, before a request leaves your perimeter.

Immutable audit

A WORM-backed log of every token, tool call and dollar — streamable to your SIEM in real time.

No training on your data

Your prompts and completions are never used to train any model — ours or a provider's. Neutral means neutral.

Compliance

Security & compliance.

SOC 2 Type II is in progress; the architecture is built to the controls today.

SOC 2 Type II · in progress EU residency Encryption in transit No training on your data DPA available
Sub-processors & status

Transparent by default.

We publish our sub-processor list and keep a live status page. Request our DPA and security questionnaire responses any time.

Request DPA & sub-processors
ALL SYSTEMS OPERATIONAL

99.99% uptime target on the enterprise SLA. Incidents and maintenance are posted to the live status page as they happen.

Trust

Put us through your security review.