This Security Addendum forms part of the Agreement when incorporated by an Order, the MCSA or the DPA. It describes Cogrion’s security commitments for the Services and Customer Data under Cogrion’s control. Capitalised terms not defined here have the meanings in the Agreement.
The controls in this Addendum apply only to systems, personnel and Customer Data under Cogrion’s control. They do not apply to Customer’s cloud environment, Customer-selected providers, Customer configurations, Customer code or Customer-managed credentials. Security is a shared responsibility. No control eliminates all risk, and this Addendum does not create a guarantee that a security incident, service interruption or data loss will never occur. All liability and remedies are governed exclusively by the MCSA.
1. Security programme
Cogrion will use commercially reasonable efforts to maintain an information-security programme proportionate to the nature of the generally available Services and the risks to Customer Data under Cogrion’s control. The programme will assign security responsibilities, establish appropriate policies, assess material risks, and review relevant controls periodically.
2. Personnel security
- Require personnel with access to Customer Data to be bound by confidentiality obligations.
- Provide security and privacy awareness training appropriate to roles.
- Use role-based authorisation and promptly adjust or revoke access when responsibilities change or employment ends.
3. Access control
- Apply least-privilege and need-to-know principles to administrative access.
- Use individual identities and appropriate authentication controls for privileged access.
- Review privileged access periodically and log material administrative activity where technically feasible.
- Restrict production access to authorised personnel for approved operational, security or support purposes.
4. Encryption and communications
Cogrion will use industry-standard encryption for Customer Data transmitted over public networks and for Customer Data stored under Cogrion’s control where technically supported and appropriate. Key management and encryption within Customer’s cloud environment remain allocated as described in the Order, Documentation or shared-responsibility model.
5. Secure development and change management
- Maintain documented development and change practices appropriate to the Services.
- Review material code or configuration changes before production release using automated or manual controls.
- Address identified vulnerabilities according to risk and maintain controls intended to prevent unauthorised software changes.
- Separate development and production access where reasonably practicable.
6. Vulnerability and malware management
Cogrion will maintain processes to identify, assess, prioritise and remediate vulnerabilities affecting components under its control. Cogrion may use automated scanning, dependency checks, penetration testing or other risk-based techniques. Cogrion will not publish vulnerability details, test results or remediation timelines that could increase security risk.
7. Logging and monitoring
Cogrion will maintain logging and monitoring appropriate to detect material unauthorised activity, support investigations and operate the Services. Log content, availability and retention depend on the Service, deployment model and Customer configuration.
8. Availability, backup and recovery
Cogrion will maintain business-continuity and recovery procedures appropriate to components under its control. Backup and recovery responsibilities for Customer Data stored in Customer’s cloud environment remain with Customer unless the applicable Order expressly assigns them to Cogrion. Service-level commitments, if any, are stated in the Support and SLA Policy or Order.
9. Incident response
Cogrion will maintain an incident-response process to identify, contain, investigate and remediate material security incidents. Cogrion will notify Customer of a confirmed incident affecting Customer Data as required by the DPA or applicable law and will provide reasonable cooperation. Cogrion may withhold information that would compromise security, legal privilege, other customers or an active investigation.
10. Suppliers
Cogrion will apply risk-based diligence and written security or confidentiality obligations to relevant suppliers. Subprocessors that process Customer Personal Data are governed by the DPA.
11. Assurance information
Upon reasonable request and subject to confidentiality, Cogrion may provide then-current independent assurance reports, certifications, penetration-test summaries or security questionnaires that are available and relevant to the Services. Cogrion is not required to disclose source code, detailed network diagrams, vulnerability data, information concerning other customers or information that would materially weaken security.
12. Customer responsibilities
- Secure Customer accounts, devices, credentials, networks and cloud environments.
- Configure identity, access, encryption, logging, network, backup, retention and data-location settings allocated to Customer.
- Provide only data that Customer is authorised to process and avoid unsupported sensitive or regulated data.
- Review alerts, maintain authorised-user lists, apply updates under Customer’s control and notify Cogrion promptly of suspected misuse or compromise.
- Implement appropriate business continuity, export and recovery arrangements for Customer-controlled data and infrastructure.
13. Changes
Cogrion may update this Addendum to reflect evolving technologies, threats and practices, provided it does not materially reduce the overall security of the applicable Services during a current subscription term. Material changes will be handled in accordance with the Agreement.