Security & Trust

A control you can hand to your auditor, your insurer, and your board.

COSIGN is infrastructure that sits in front of money movement. It is built to be deterministic, inspectable, and provable — so the same record that stops fraud is the evidence behind your compliance and your guarantee.

Where COSIGN sits

COSIGN installs as a thin intercept at the approval step of your existing bank, ERP, AP, payroll, and identity systems — not a rip-and-replace. We act on the authorization decision, not on your ledgers of record. Where possible we read the minimum context needed to describe a pending action (amount, beneficiary, initiating system) and we do not store raw banking credentials.

How a cosign works (passkeys / WebAuthn)

A cosign is a FIDO2/WebAuthn assertion produced by a hardware-bound passkey on a registered device, released only after a local biometric or PIN. The signing challenge is bound to the exact transaction — amount, beneficiary, and a server-issued nonce — so a signature for one wire cannot be replayed against another.

Because the private key never leaves the secure element and there is no shared secret to phish, a synthetic voice or video on a call has nothing to produce. This is the property that makes the control deterministic rather than probabilistic.

The immutable ledger

Every intercept and every approval is written to an append-only, hash-chained record: who approved, what, when, from which device, and the cryptographic material that proves it. Each entry commits the hash of the prior entry, so any tampering breaks the chain and is detectable.

That record is exportable as your audit trail, your “documented & monitored” control evidence for SOX-style segregation of duties, and the proof behind the COSIGN guarantee. Enterprise deployments can run the ledger on-premises or anchor it to an external transparency log.

Data handling

Data is encrypted in transit (TLS 1.2+) and at rest. We practice data minimization: we capture the metadata required to describe and authorize an action, not the contents of your accounts. Access is least-privilege and logged. We do not sell data, and we do not use customer transaction data to train models.

Compliance posture

COSIGN's SOC 2 Type II program is in progress; status and the current report are available under NDA on request. The control maps cleanly to the out-of-band approval requirement that cyber-insurers increasingly expect before covering a social-engineering loss, and to internal-control frameworks your auditors already test against.

Responsible disclosure

We welcome coordinated disclosure. Email security@usecosign.com with findings; we aim to acknowledge within one business day. Please do not test against production tenants without written authorization.

This page describes current and planned posture and will evolve as the SOC 2 program completes.