Security

Last updated 2026-07-18 · the architecture, controls, and posture for cogos.5ceos.com

This page consolidates the security claims the landing page makes into one document procurement teams can read in a single sitting. Each item is tagged honestly: shipped means the runtime enforces it today and it's customer-verifiable; partial means it's enforced for the listed scope but has named exclusions; roadmap means committed-direction but not yet shipping.

Deeper reading — audit-ready evidence

Three companion documents, all in draft as of the "Last updated" date above, all served as raw markdown so the source of truth stays under version control:

Note: /trust is a separate, live transparency dashboard (uptime, hash-chain checkpoints, continuous probes, advisories). The three docs above are architectural + verifier material; /trust is operational state.

Data at rest shipped

Data in flight shipped

Per-response cryptographic receipts shipped

Every /v1/* response carries two independent receipts that bind the response to the running build and the audit chain head:

Inference path shipped

Image supply chain roadmap

Customer authentication shipped

Cross-origin resource sharing (CORS) shipped

Tenant isolation shipped

Hash-chain checkpoint anchoring shipped

Runtime hardening shipped

Key management partial

SOC 2 posture — what's actually happening now in progress

We name this section honestly. SOC 2 Type II attestation is not signed; that requires a third-party audit that hasn't been booked yet. But every control on the SOC 2 Trust Service Criteria (Security · Availability · Confidentiality) that we can execute pre-audit is either shipping, documented, or actively being built. This section is what we can defend to a security review that asks “so what have you actually done?”

Security TSC — substantially in place

Confidentiality TSC — substantially in place

Availability TSC — being built

Formal attestation path — committed, unbooked

For procurement reviews: everything above is verifiable today. Send your security questionnaire to support@5ceos.com with subject “Security Questionnaire · [Company]”; we return responses within 3 business days along with control-architecture mapping to your frameworks (SIG Lite, CAIQ, or your custom form).

Responsible disclosure

Found a security issue? Email support@5ceos.com with the subject line "Security Disclosure". Include reproduction steps and an estimate of the affected tenants. We acknowledge within 1 business day, triage within 3 business days, and we'll keep you informed through the fix. We do not currently run a paid bug-bounty program; we publicly credit researchers in /trust advisories after the fix ships, with the researcher's permission.