Security
Security at Cognify Works
How we approach security, access, technology operations, and responsible data handling across Cognify Works.
Last updated: September 2026
Cognify Works uses layered technical and operational controls appropriate to the services being provided. This page describes our general approach. It is not a certification, audit report, or guarantee of security. Detailed security requirements for a customer engagement are governed by the applicable agreement, scope, architecture, or product terms.
Our security approach
We use layered technical and operational controls appropriate to the services being provided. Managed IT, Microsoft services, hosted products, and custom solutions do not all use identical environments or controls.
Our approach typically includes:
- identity and access management based on role and need
- least-privilege and role-based access principles
- cloud and platform security appropriate to the environment
- secure development practices and environment separation where we build or operate software
- monitoring, logging, and backups appropriate to the service
- reducing unnecessary data collection
- reviewing data flows before production use
Identity and access
Where we operate or administer technology environments, we apply identity and access practices such as least-privilege access, role-based permissions, and multi-factor authentication where appropriate. Access is limited based on role and need. Customer-managed environments follow the access model defined for that engagement.
Cloud and Microsoft security
Cognify Works often works in Microsoft-centered environments. Depending on the engagement, that work may include Microsoft Entra identity and MFA, Conditional Access, Microsoft Defender, Microsoft Intune, Azure security controls, and Microsoft 365 security configuration.
Not every customer uses every Microsoft product. Microsoft does not certify or guarantee Cognify Works through this page.
Secure development and operations
For software and hosted solutions we build or operate, we use practices such as environment separation, secrets management, and review of data flows before production use. Operational controls may also include monitoring, audit logging, and backups appropriate to the service. These practices are applied according to the architecture and scope of the work, not as a single identical control set across every product or customer environment.
Website data
For the public website, we collect only the information needed to respond to inquiries, understand website usage, and protect the site from abuse.
See our Privacy Policy for more detail.
Customer environments and product data
Some Cognify Works products and custom solutions may process business, operational, education, MSP, IT service, or workflow data. Those engagements require separate written agreements that define:
- data ownership
- permitted use
- hosting responsibilities
- access controls
- retention expectations
- support responsibilities
- data processing obligations
Education and regulated workflows
Some hosted products may support education or other regulated workflows. We do not claim blanket compliance or certification from this website alone. Compliance responsibilities, including FERPA-related handling where applicable, must be addressed in the customer agreement and implementation process.
AI and workflow data
When AI is used in a customer solution, the intended use, data flow, model behavior, review process, and guardrails should be defined during implementation. We avoid treating AI as a black box for business-critical decisions without appropriate oversight.
Vendors and platforms
Cognify Works may use cloud hosting, email, analytics, storage, AI model providers, and other vendors to operate the website and deliver services. Customer-specific vendor and subprocessor details should be addressed in the relevant agreement or data processing terms.
Incident response
If a security issue affects customer data, we follow incident-response principles appropriate to the situation. Response obligations and notification procedures follow the applicable customer agreement and legal requirements.
Contact
For security questions, contact hello@cognify-works.com.
