Security • Machines Propose. Humans Confirm.

Machines propose.
Humans confirm.
Auditors verify.

Kosmos surfaces hidden relationships across your infrastructure, deployments, and data. AI proposes. Humans verify. Every decision is explainable, auditable, and built for enterprise security.

Go to Trust Center →
Continuously correlates signals across your stack.
Review with full evidence and context.
Explainable decisions. Immutable logs.
0 findings
High severity DAST scan · Mar 2026
TLS 1.2+
Encryption In transit, at every hop
OAuth 2.0
Integrations Read-only scopes by default
SOC 2
Type 1 targeted Audit engaged · Jun 2026
Infrastructure

Infrastructure & application security.

Kosmos runs on managed GCP services end-to-end. Fewer surfaces to harden, fewer surfaces to breach — with CSRF, rate limiting, and PII redaction enforced at the app layer.

PLATFORM

GCP-native architecture

Deployed entirely on Google Cloud — Cloud Run, Cloud SQL (PostgreSQL), Google Cloud Storage, DuckDB, and Vertex AI. No third-party infrastructure exposure.

IDENTITY

Authentication

Firebase Auth for user sessions. Backend validates tokens on every API call. Service-to-service auth via GCP IAM service accounts.

ABUSE

CSRF & rate limiting

State token validation on all OAuth flows. Double-submit cookie pattern enforced on all state-changing requests. IP-based rate limits on all endpoints.

ENCRYPTION

Encryption everywhere

TLS 1.2 and above for data in transit. OAuth tokens encrypted at the application layer. Secrets in GCP Secret Manager with version control.

TENANCY

Multi-tenant isolation

Defense-in-depth isolation at the application layer. Each organization’s data is scoped by org identifier across all storage systems.

OBSERVABILITY

Audit trail & PII redaction

Auth events, integration activity, and RCA generation are logged to a structured audit trail. Emails and credentials are redacted before emission.

PLATFORM

GCP-native architecture

Deployed entirely on Google Cloud — Cloud Run, Cloud SQL (PostgreSQL), Google Cloud Storage, DuckDB, and Vertex AI. No third-party infrastructure exposure.

IDENTITY

Authentication

Firebase Auth for user sessions. Backend validates tokens on every API call. Service-to-service auth via GCP IAM service accounts.

ABUSE

CSRF & rate limiting

State token validation on all OAuth flows. Double-submit cookie pattern enforced on all state-changing requests. IP-based rate limits on all endpoints.

ENCRYPTION

Encryption everywhere

TLS 1.2 and above for data in transit. OAuth tokens encrypted at the application layer. Secrets in GCP Secret Manager with version control.

TENANCY

Multi-tenant isolation

Defense-in-depth isolation at the application layer. Each organization’s data is scoped by org identifier across all storage systems.

OBSERVABILITY

Audit trail & PII redaction

Auth events, integration activity, and RCA generation are logged to a structured audit trail. Emails and credentials are redacted before emission.

Data Handling

Minimum scope. Defined retention. Clean exit

We read what we need to correlate signals, store what we need to learn from them, and delete everything on your word. No shadow copies, no surprises.

What Kosmos reads

Signal metadata from connected systems — issues, tickets, commits, messages, and traces. Minimum required scopes, read-only. Sources include Jira, Salesforce, ServiceNow, Zendesk, GitHub, Bitbucket, Slack, Linear, Pylon, and OpenTelemetry.

What Kosmos reads

What Kosmos stores

Signal metadata and correlation results only — no duplication of raw source data beyond what correlation requires. Stored in Cloud SQL (PostgreSQL), Google Cloud Storage, and DuckDB.

What Kosmos stores

Data deletion

On contract termination, all customer data is deleted within 30 days. Hard-delete is available on written request to security@kosmoslabs.ai

Data deletion

Subprocessors

Kosmos processes data on Google Cloud Platform (compute, storage, networking), Vertex AI (Gemini 2.5 Flash for RCA generation and text embeddings), and Firebase Auth (user authentication). A complete subprocessor list including notification providers is available on request.

Subprocessors
Compliance & Legal

Documents & response SLAs.

All security and compliance documents are reviewed quarterly. Questionnaires and DPA requests are routed to a dedicated security alias with a five-business-day SLA.

Privacy policy

Data collection, use, and retention practices

View

Terms of service

Platform usage terms and conditions

View

Security questionnaire support

We respond to VSAs, CAIQ, and custom security questionnaires within 5 business days

View
Operational Intelligence Platform

See What Your Team Has Been Missing

Connect your Salesforce and Jira in one call. In 14 days, we will show you 90 days of patterns your team has been chasing manually.

Request a 14-Day Trial