Your Data is in Safe Hands

Immigration data is among the most sensitive personal information that exists. We built Kognitico from the ground up with enterprise-grade security, strict data isolation, and full auditability — because the stakes demand it.

Explore Our Trust Center

Certifications & Compliance

SOC 2 Type II In Progress
GDPR
Compliant
CCPA
Compliant
AWS
Hosted

Security Principles

Encryption Everywhere

All data encrypted at rest using AES-256 and in transit using TLS 1.2+. Applies to every database, file store, and API endpoint.

Zero Trust Access

No user or system is inherently trusted. Every access request is verified, scoped to the minimum required permissions, and logged.

Full Audit Trail

Every state transition, human approval, and AI action is logged in an append-only audit trail — retained for 90 days after case closure.

We Never Train on Your Data

Your chat inputs, uploaded immigration documents, and case data are never used to train Kognitico's AI models or any third-party models without explicit consent.

Firm-Level Data Isolation

Every law firm's data is completely walled off from every other firm. A user at one firm can never see, search, or access any data belonging to another firm — by design, not just by policy.

24/7 Monitoring

AWS CloudWatch monitors all infrastructure in real time — latency, error rates, and anomalies — with automated alerting and structured logging for all AI interactions.

Amazon Web Services

Powered by the world's most secure cloud

Kognitico runs entirely on Amazon Web Services — the infrastructure trusted by the US Government, global banks, and Fortune 500 companies. AWS holds over 143 security certifications and compliance programs, which directly benefit every Kognitico customer.

  • Physical datacenter security managed by AWS
  • AWS-native DDoS mitigation at network edge
  • Automatic infrastructure patching and updates
  • 99.99% uptime SLA backed by AWS availability zones

Continuous Compliance

35 security controls monitored

Our Trust Center tracks 35 active security controls in real time. All controls are aligned to SOC 2 trust service criteria and monitored continuously through automated tooling.

View live controls →
Acceptable Use Policy Access Rights Management Asset Inventory Change Management Configuration Management Patch Management Credential Management Data Classification Data Privacy Controls Data Retention & Destruction Encryption Standards Incident Response Network Security Physical Security (AWS) Risk Assessment Security Awareness Training Third-Party Risk Management Vulnerability Management

35

Monitored Controls

100%

AWS-Hosted Infrastructure

24/7

Continuous Monitoring

Frequently Asked Questions

No. Your chat inputs, uploaded documents, questionnaire answers, and immigration records are never used to train Kognitico's AI models or any third-party models without your explicit written consent.
All data is stored and processed in the United States on Amazon Web Services infrastructure. We do not transfer personal immigration data outside the US.
Uploaded documents (passports, I-94s, pay stubs, etc.) are stored in Amazon S3 with server-side AES-256 encryption and accessed only via signed URLs scoped to the specific case and user. Documents never leave the secure storage boundary except through authenticated API calls.
No. Each law firm's data is completely isolated from every other firm on the platform. When you log in, you can only ever see your firm's cases, clients, and documents. There is no way — through the application or otherwise — for any user to access data belonging to a different firm. This isolation is enforced at the infrastructure level, not just through application permissions.
When you delete a chat or account, data is immediately removed from active systems. Encrypted backups are permanently overwritten within 30 days. You may request a full data export before deletion.
Never. Every USCIS submission requires explicit human approval through a mandatory attorney review gate. The AI system is architecturally prevented from auto-submitting to any government portal. Attorneys remain solely responsible for all filings.
We will notify affected users and applicable regulatory authorities as required by GDPR, CCPA, and applicable US state laws. Our incident response procedures are defined and tested as part of our SOC 2 audit process.

Questions About Security?

Review our full compliance documentation in our Trust Center, or reach out to our security team directly.