Operational policies
These four policies are the documentation baseline for the SOC 2 Trust Service Criteria we're actively closing on. Each is a live document, versioned, reviewed on a stated cadence, and available under NDA to prospects doing a security review.
Full security posture at /security. Trust Center at /trust. Sub-processor list at /sub-processors.
Top-level security posture · principles · controls summary. Parent to the other three.
Source: docs/policies/information-security-policy.md in the cogos-api repo. Available on request under NDA.
Who gets access to what · MFA everywhere · onboarding + offboarding · quarterly access review cadence.
Source: docs/policies/access-control-policy.md in the cogos-api repo. Available on request under NDA.
How changes reach production · deploy gates · rollback discipline · prohibited ad-hoc edits.
Source: docs/policies/change-management-policy.md in the cogos-api repo. Available on request under NDA.
Severity levels · detection sources · notification obligations · postmortem template.
Source: docs/policies/incident-response-policy.md in the cogos-api repo. Available on request under NDA.
Enterprise procurement or security-review teams: email support@5ceos.com with subject “Policy Pack Request · [Company]”. We’ll send the four policies + control-architecture mapping to your security framework (SIG Lite · CAIQ · custom form) within 3 business days.
Under NDA. Non-customer redistribution prohibited per the response letter.