Security

Independently tested, certified,
and built that way.

Dactana has been penetration tested by an independent CREST-accredited firm and Cogitait is certified under Cyber Essentials, the UK Government-backed scheme. The controls behind that are already in place, running and checked daily. Here is what they cover.

2026 · Independent CREST-accredited firm

Professionally penetration tested

An independent, CREST-accredited security firm completed a penetration test of the Dactana platform in 2026, covering the web application and the AI assistant itself. Findings raised during the engagement were remediated and retested within the test window and the final report closed with no outstanding findings.

Summary available under NDA. Repeated at least annually and after major architectural change.

Cyber Essentials certified

UK Government-backed scheme · Certified August 2026

Cyber Essentials certified

Cogitait is certified under Cyber Essentials, the UK Government-backed scheme that verifies the core technical controls every organisation should have in place: firewalls, secure configuration, access control, malware protection and patch management.

Whole organisation in scope. Recertified annually.

Certification underway · Target early 2027

ISO 27001 in progress

The controls are implemented, evidenced and monitored daily on our compliance platform. What remains is evidence collection across the audit period and the independent audit itself, not new controls.

Live progress shared under NDA.

Security posture

Security underpins everything we do

We are not building a security programme to pass an audit; we are having the programme we already run independently tested and certified.

Your data

  • Encrypted at rest and in transit everywhere, including enforced TLS to every database.
  • Hosted in the EU, with strict isolation between customer organisations.
  • Single sign-on and multi-factor authentication for your users.
  • Documented retention and auditable deletion. Every erasure produces a verifiable record.
  • Automated backups with point-in-time recovery.

Our platform

  • Production fully isolated from development, in separate cloud accounts with organisation-wide guardrails.
  • All infrastructure defined as code and peer reviewed. No untracked changes.
  • No public administrative access: no open SSH or RDP anywhere. Admin access runs over identity-verified private channels only.
  • A web application firewall in front of the product, with configuration monitored continuously.

Our people and devices

  • Single sign-on and multi-factor authentication enforced for every member of staff.
  • Administrative work on separate privileged accounts. Least privilege by default.
  • Every device company-owned, centrally managed, fully encrypted and protected by endpoint detection and response. Personal devices are not used for company work.
  • One identity source, so offboarding revokes all access in a single step.

How we build

  • Every change peer reviewed and passed through automated checks before it ships.
  • Dependencies, code and container images scanned automatically on every change.
  • Findings remediated to defined timescales under a documented vulnerability management process.
  • Security is part of the engineering workflow, not a separate gate.

Behind it all: a full information security policy suite, a maintained risk register, incident response and business continuity plans and daily automated monitoring of our controls.

In the product

Safeguards across the whole workflow

From execution boundaries to access control and full visibility of every run.

Web traffic protection

Incoming traffic is filtered before it reaches core services, with web application firewall controls and rate limiting.

Encryption in transit

Connections are encrypted in transit, including external access and internal service communication.

Encryption at rest

Stored data is encrypted at rest across key platform services, including databases and file storage.

Private service boundaries

Core compute and data services run in private network segments, not exposed to the public internet.

Controlled file access

Sensitive files are reached through time-limited signed links, never open public URLs.

Secure secrets handling

Credentials and keys are managed through dedicated secret controls, not embedded in application code.

1

Isolated analysis environments

Analytical work runs in isolated environments separated from production systems, containing failures.

2

Guardrails and limits

Built-in limits and circuit breakers keep execution predictable and prevent unbounded retries or resource use.

3

Access control and data separation

Access is governed by organisation and permissions, so users only work with data they are authorised to use.

4

Observability and auditability

Every analysis generates a trace of what happened, including quality checks, timing and status, for review.

Privacy

Your data stays yours

Dactana reads, checks and reports. It does not copy, retain or learn from your data.

Your data stays in your warehouse

Dactana connects with read-only credentials and runs queries where the data lives, with row limits and timeouts.

Only results leave

What comes back is the finding and the fact table behind it, not a copy of your data.

Nothing learns from your queries

There is a clear separation between your data and model behaviour. The models do not learn from your questions or your data.

No question trail on your data

No prompt history is retained against your business data.

Credentials, governed

Connection credentials go through a secure credential workflow, never pasted into a chat or a shared document.

Separated by organisation

Each organisation and assistant is isolated, with access control built in.

Common questions

Has Dactana been penetration tested?

Yes. An independent CREST-accredited firm tested the Dactana platform in 2026, including the AI assistant itself. Every finding was remediated and retested within the engagement and the report closed with nothing outstanding. We share the summary under NDA and repeat the test at least annually.

Are you Cyber Essentials certified?

Yes. Cogitait is certified under Cyber Essentials, the UK Government-backed scheme, as of August 2026. We are working towards ISO 27001 certification, targeted for early 2027, with progress tracked daily on our compliance platform.

Where does the analysis run?

In an isolated analysis environment, separate from production systems, with limits on retries and resource use. Your warehouse is only ever queried read-only and only the results come back.

Can we see your policies?

Yes. A full information security policy suite, a maintained risk register and incident response and business continuity plans sit behind the controls. Under NDA we share the policies, the penetration test summary and our live ISO 27001 progress.

How can you trust the answers? →

Ask for the security pack

Under NDA we share the penetration test summary, our policies and our live ISO 27001 progress.