Secure by architecture.
Cohesor sits on the hot path of your most sensitive traffic — so it's built to hold the least, encrypt the rest, and prove every request. No training on your data, ever.
Keys, handled right
Provider keys are encrypted at rest and never returned to the browser. Gateway keys are shown once and stored only as a SHA-256 hash.
Client-side OAuth
MCP OAuth tokens stay on the client. Cohesor brokers tool calls without warehousing your third-party credentials.
Tenant isolation
Every workspace is isolated — keys, budgets, caches and audit logs never cross tenant boundaries.
Policy before egress
PII redaction, prompt-injection scanning and data-residency pinning run in-gateway, before a request leaves your perimeter.
Immutable audit
A WORM-backed log of every token, tool call and dollar — streamable to your SIEM in real time.
No training on your data
Your prompts and completions are never used to train any model — ours or a provider's. Neutral means neutral.
Security & compliance.
SOC 2 Type II is in progress; the architecture is built to the controls today.
Transparent by default.
We publish our sub-processor list and keep a live status page. Request our DPA and security questionnaire responses any time.
Request DPA & sub-processors →99.99% uptime target on the enterprise SLA. Incidents and maintenance are posted to the live status page as they happen.