Is this your company?Buyers are checking Cobrief here. Claim cobrief.no free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Modern organizations use Cobrief to streamline their procurement processes. Over 2500 leading companies trust Cobrief to handle their critical data securely. Cobrief operates a continuously monitored and 3rd-party audited security program. We are ISO 27001 certified and fully GDPR compliant. This page provides access to trust resources including our compliance certificates, sub-processors, policies, and real-time status against our security controls. 1. ✅ ISO 27001 Certified 2. 🇪🇺 GDPR Compliant (Data hosted in EU/EEA) 3. 🔒 Encrypted at rest and in transit
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Cobrief SOC 2 compliant?
Cobrief is SOC 2 compliant. On SOC2C this listing is Listed.
Is Cobrief GDPR compliant?
According to Cobrief's public trust center, Cobrief is GDPR compliant. On SOC2C this listing is Listed.
Is Cobrief ISO 27001 certified?
According to Cobrief's public trust center, Cobrief is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Cobrief's SOC 2 for a vendor risk assessment?
Yes. Cobrief's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Cobrief penetration tested?
Cobrief hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Cobrief secure?
Security isn't a single yes/no, but Cobrief is SOC 2 compliant and holds GDPR, ISO 27001. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Cobrief have a bug bounty or vulnerability disclosure program?
Cobrief hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@cobrief.no or via a /security page (Cobrief lists a security contact).
Who are Cobrief's subprocessors?
Cobrief lists 12 subprocessors on its trust center, including Auth0, Google Cloud Platform, Mailgun, Intercom, Amazon Web Services. Buyers use this for fourth-party risk review.
Where does Cobrief host or store data?
Cobrief hosts on AWS, GCP, Azure, and handles Employee personally identifiable information. Data residency details are on its trust center.
Where is Cobrief's trust center or security page?
Cobrief's trust center is at https://trust.cobrief.no. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Do you use my data to train your AI models?
No. We have strict agreements with our LLM providers Microsoft Azure OpenAI and Google Cloud that prohibit the use of customer data for model training. Your data remains yours and is strictly used to generate responses within your specific context.
Does the AI retain my data? (Zero Retention)
We enforce a "Zero Retention" policy for data sent to our LLM providers. Data sent for inference is processed in memory and is not stored by the model provider. We utilize enterprise APIs that guarantee data privacy, unlike consumer versions of AI tools.
How do you prevent the AI from leaking data between customers?
We use a RAG (Retrieval-Augmented Generation) architecture. The AI only processes the specific context snippets we retrieve from your isolated data environment to answer a query. It has no "memory" of other customers' data.
What is Cobrief's approach to use of AI?
Cobrief always focus on the following key values when working with AI. - Privacy: All data is processed on pre-trained models in Europe. - Ownership to data: Our customers own their own data. - Knowledge and competence: We keep ourselves updated so you can always trust your company uses the best models and approaches. - Reliability: You should be able to trust the information our AI-models provide. - Product-driven AI: We use AI whenever we can to make the user experience in our product as best as it can be. Read more in our Norwegian article https://www.cobrief.no/blogg/var-tilnaerming-til-ai
How is my data encrypted?
We employ strong cryptography throughout the entire data lifecycle to protect confidentiality and integrity. - Data at Rest: All confidential customer data stored on our servers (including databases and backups) is encrypted using AES-256 bit symmetric encryption. - Data in Transit: All data transmitted between your devices and our services is encrypted via TLS (Transport Layer Security) using industry-standard ciphers (Grade B or higher). - Standards: Our cryptographic controls are implemented in accordance with industry best practices, including NIST SP 800-57 recommendations. - Passwords: User credentials are hashed and salted using strong algorithms like Bcrypt or Argon2.
Where is my data physically stored?
Customer data is hosted in the EU/EEA area, primarily in Google Cloud Belgium (europe-west1). This ensures compliance with European data residency requirements. Our hosting provider is SOC 2 Type II and ISO 27001 certified.
What security measures are in place to protect customer data?
Cobrief has a comprehensive set of security measures in place to protect customer data. You can review our externally committed security controls (as a part of our ISO 27001 certification) at our Trust Center: https://trust.cobrief.no/controls. Key measures include: - Encryption: Data is encrypted both in transit (TLS 1.2+) and at rest (AES-256). - Access Control: We apply the principle of least privilege. Multi-factor authentication (MFA) is mandatory for all administrative access. - Secure Development: Our software is developed in-house following secure coding principles, including code reviews and continuous vulnerability scanning. - Monitoring: We use continuous monitoring tools to ensure our security controls are effective 24/7. - Resilience: We perform regular backups of all systems and test our recovery procedures to ensure service availability. Our Trust Center has additional information about our security practice.
How do you handle security incidents?
We have a formal Incident Response Plan (IRP) in place. In the event of a confirmed data breach affecting your data, we are committed to notifying you without undue delay, in accordance with GDPR requirements
Is Cobrief ISO 27001 Certified?
Yes. Cobrief is ISO 27001 Certified. ISO 27001 is an international standard for information security management systems. It provides requirements for establishing, implementing, maintaining and continually improving an organization's information security management.
Can I subscribe to new sub-processors?
Yes. You can subscribe to new sub-processors from the Profile-page within the Cobrief applications.
What is your Disaster Recovery (DR) strategy?
Cobrief maintains a formal Business Continuity and Disaster Recovery (BC/DR) Plan designed to restore critical services rapidly in the event of a major outage or natural disaster. - Redundancy and backups: We utilize the distributed nature of our cloud providers (e.g., Google Cloud/AWS) to ensure high availability. Critical data, such as SQL databases, is backed up continuously with Point-in-Time Recovery capabilities , and we maintain off-site backups (e.g., AWS S3) for additional redundancy. - Testing: We perform a full Disaster Recovery test, including backup restoration verification, on an annual basis to ensure our procedures are effective. - Resilience: Our plan covers specific scenarios ranging from public cloud outages to HQ unavailability, ensuring our team can operate remotely and continue supporting the platform effectively.
Does Cobrief support Single Sign-On (SSO)?
Yes. Users sign in with their existing Microsoft (work/school) or Google account, handled through our managed identity layer (Auth0) using standard OpenID Connect / OAuth 2.0 against the Microsoft Identity Platform (v2) and Google. For a Microsoft 365 or Google Workspace organisation this is, in effect, federated SSO: employees authenticate with the account they already use, and there is no separate Cobrief password to manage. Authentication takes place entirely at Microsoft or Google — Cobrief never sees or stores passwords. The only information returned to Cobrief is basic identity (name, email address, and user principal name); we do not read group memberships, directory data, mailboxes, or files.