Trust & security

Trust and security at Cosmo

Cosmo is SOC 2 Type II compliant and certified to ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 20000-1. The platform runs on AWS with isolated production, sandbox and development environments, encrypts all data at rest and adds field-level encryption for personal data.

Certifications

Independently audited and certified

SOC 2 Type II
Security, availability and confidentiality controls
ISO/IEC 27001
Information security management
ISO/IEC 27017
Cloud security controls
ISO/IEC 27018
Protection of personal data in the cloud
ISO/IEC 20000-1
IT service management
Infrastructure

Where and how the platform runs

Hosted on AWS

The Cosmo platform runs on Amazon Web Services, with Frankfurt (eu-central-1) as the primary region.

Isolated environments

Production, sandbox and development run in separate, isolated networks, with separate credentials for each environment.

Resilient data storage

The production database runs across multiple availability zones, with point-in-time recovery for the last 30 days.

Perimeter protection

A web application firewall and continuous threat detection protect production traffic.

Data protection

How data is protected

Encryption at rest

All databases are encrypted at rest. Personal data is additionally encrypted at field level with AES-256.

Access control

Multi-factor authentication is required for all administrative access, and audit logs are retained for 12 months.

Privacy by law

Personal data is handled under the DIFC Data Protection Law No. 5 of 2020. See the Privacy Policy for details.

API security

Secure by default for developers

OAuth 2.0

API access uses the OAuth 2.0 client credentials flow, with a separate secret for sandbox and production.

Safe retries

Every transaction carries a reference number, so a retried request is never processed twice.

Authenticated webhooks

Webhooks to clients and partners support Basic, OAuth or signature-based authentication.

FAQ

Security questions, answered.

Is Cosmo SOC 2 compliant?

Yes. Cosmo is SOC 2 Type II compliant, covering security, availability and confidentiality controls.

Which ISO certifications does Cosmo hold?

Cosmo is certified to ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and ISO/IEC 20000-1, covering information security management, cloud security controls, protection of personal data in the cloud and IT service management.

Where is Cosmo hosted?

The Cosmo platform runs on Amazon Web Services, with Frankfurt (eu-central-1) as the primary region. Production, sandbox and development environments are isolated from each other.

How does Cosmo protect personal data?

All databases are encrypted at rest, and personal data is additionally encrypted at field level with AES-256. Personal data is handled under the DIFC Data Protection Law, and administrative access requires multi-factor authentication.

How do I request Cosmo's SOC 2 report or ISO certificates?

Email contact@cosmopoints.com with your company name and the documents you need, and the Cosmo team will follow up.

Need security documentation?

Request the Cosmo SOC 2 report or ISO certificates for your vendor review.

Request documents →Talk to the team