Security

Security practices

A factual overview of the safeguards used to protect Cognimark applications and authorized clinical data.

Last reviewed August 5, 2026

01

Layered safeguards

Security controls are applied across infrastructure, identity, software delivery, monitoring, and recovery instead of relying on a single product or boundary.

Protected infrastructure

Application and data workloads use segmented cloud networks, encrypted transport and storage, and centrally managed secrets.

Controlled access

Managed authentication, application-specific authorization, organization boundaries, and explicit EHR identity links limit access.

Monitored operation

Central audit records, threat detection, vulnerability scanning, and retained security evidence support investigation and response.

Disciplined delivery

Infrastructure as code, short-lived deployment credentials, automated validation, and recovery testing govern production changes.

02

Data protection

  • Public traffic is encrypted in transit using current TLS configurations.
  • Managed clinical stores, databases, backups, and restricted intake archives use encryption at rest and private access controls.
  • Clinical data is separated by application and organization boundaries, with product-specific storage and authorization.
  • Public forms warn against submitting PHI, credentials, or sensitive technical details and use separate intake paths for business and compliance reports.
03

Identity and access

  • Individual managed identities are used instead of shared product accounts.
  • Product grants, organization membership, and application authorization are evaluated separately.
  • EHR users must be explicitly linked to an authorized Cognimark identity before an EHR Launch can establish an application session.
  • Production deployments use short-lived, repository-bound credentials and narrowly scoped runtime roles.
04

Secure operations

  • Production application workloads use segmented cloud networks, private service routes, and controlled security-group relationships.
  • Central audit records, cloud threat detection, dependency monitoring, and container and host vulnerability scanning support review and response.
  • Infrastructure and application changes are version controlled, automatically validated, and deployed through defined CI/CD identities.
  • Backups, point-in-time recovery, retained security events, and documented restore tests support continuity and investigation.
05

Scope and assurance

Cognimark maintains security and privacy controls intended to support its HIPAA Business Associate obligations and the SOC 2 Security criteria. Exact service scope, permitted uses, customer responsibilities, and contractual commitments are defined in the applicable agreements.

This page is a security overview, not a certification, audit report, or replacement for an executed agreement.
06

Reporting and support

Use the anonymous reporting channel for suspected security, privacy, compliance, ethics, fraud, or workplace concerns. Use the business contact channel for product access and support. Do not place PHI, credentials, private keys, or exploit details in either public form; Cognimark will arrange a suitable channel for sensitive follow-up.