SOC2C

Is this your company? Buyers are checking S2 Cognition LLC here. Claim s2cognition.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
S2 Cognition LLC logo

S2 Cognition LLC

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

S2 Cognition LLC is SOC 2 compliant. S2 Cognition LLC also holds PCI DSS, CMMC, CSA STAR, CCPA, and PIPEDA.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to S2 Cognition’s Trust Center. Security and privacy aren’t afterthoughts—they’re built into our product from the ground up. Our secure‑by‑design platform embeds Information Security and Data Privacy principles at every layer of our business and technology stack. Through this portal, you can explore our security and privacy posture and request access to supporting documentation. Please note that certain Trust Center materials require a valid non‑disclosure agreement (NDA), which may be completed after you submit a documentation request. Founded in 2015 by former college athletes and co

Compliance & infrastructure

PCI DSSCMMCCSA STARCCPAPIPEDA
Data handled
Customer personally identifiable informationEmployee personally identifiable information

Subprocessors

7
  • M
    Microsoft 365 · Collaboration, Communications, Productivity
    United States
  • m
    monday.com · Customer Relationship Management
    United States
  • A
    Adobe · Invoices, Legal Contracts
    United States
  • K
    Klaviyo · Marketing Communications
    United States
  • S
    Slack · Collaboration
    United States
  • A
    Authorize.net · Payment Gateway Service Provider
    United States
  • S
    Square · Payment Gateway Service Provider
    United States

Compliance leadership

The person who leads S2 Cognition LLC's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. S2 Cognition LLC's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

Scheduled System MaintenanceFeb 2026

We will be undergoing a system upgrade on Sunday, February 8th, from 00:00 UTC through 00:00 UTC on February 9, 2026. During this time, the following services will be affected: - Public Services - Portal - S2 Evaluation - Backend Services - Web API Services - Asset Management API Services - Evaluation API Services - Scoring API Services Additional details are available at: https://s2cognition.statuspage.io/

S2 Cognition Privacy Policy updatedJan 2026

S2 Cognition Privacy Policy We’ve updated our Privacy Policy to clarify how we handle SMS and mobile communications data, reinforcing our commitment to transparency and responsible data use. Key Change: SMS and Mobile Communications Privacy: We have added a dedicated section to explicitly state that mobile phone numbers and SMS opt-in data are not sold, shared, rented, or disclosed to third parties for marketing or promotional purposes. SMS opt-in information is used solely to deliver messages that users have explicitly consented to receive, such as operational, service-related, or security communications. Any SMS data processing by service providers is limited to delivering messaging services and is subject to confidentiality and data protection obligations. Mobile opt-in data is shared only as required to provide SMS services or to comply with legal requirements. This update is effective immediately. You can review the full, updated Privacy Policy and all past updates on the S2 Cognition Trust Center: https://trust.s2cognition.com/updates Your continued use of our Services constitutes acceptance of these changes. If you have questions or need additional information, please contact our Privacy team at [Privacy@s2cognition.com](mailto:privacy@s2cognition.com).

S2 Cognition will once again pursue a SOC 2 Type II third-party attestation in 2026Jan 2026

SOC 2 is a security framework that specifies how organizations should protect customer data from unauthorized access, security incidents, and other vulnerabilities. The American Institute of Certified Public Accountants AICPA developed SOC 2 around five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A SOC 2 audit report is the gold standard for third-party risk management. The SOC 2 report assures our customers and partners that we have the systems and controls in place to protect their critical business information.

S2 Cognition Successfully Renews SOC 2 Type II Compliance for 2025Nov 2025

S2 Cognition is pleased to announce the successful completion of its System and Organization Controls (SOC 2) Type II audit for this year, reaffirming our compliance with industry-leading standards for customer data security. This achievement demonstrates our continued commitment to maintaining a secure and resilient environment for our customers. Developed by the American Institute of Certified Public Accountants (AICPA), SOC 2 is an information security framework that validates controls relevant to security, availability, confidentiality, processing integrity, and privacy. The audit was completed with the support of Johanson Group LLP, a premier certification body that assists organizations in obtaining and maintaining global compliance standards. ### Why is security important at your company and what made you set out to get your SOC 2 compliance? Security is a core priority at our company because it protects sensitive information, preserves the trust of our clients, and ensures the reliability of our operations. Cyber threats continue to evolve, and strong security practices are essential for safeguarding customer data, proprietary information, and the continuity of our services. A security incident can have significant reputational, financial, and legal consequences. Our commitment to robust security practices reflects both our ethical responsibilities and our strategic…

Data Privacy Framework Re-Certification CompletedJul 2025

S2 Cognition has re-certified our compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). Our active certification is publicly available on the DPF website.

This listing is partial

5/11 details · 45%

SOC2C shows the verified essentials. 6 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Hosting
    Add where you host (AWS, GCP, Azure) and data residency.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is S2 Cognition LLC SOC 2 compliant?
S2 Cognition LLC is SOC 2 compliant. On SOC2C this listing is Listed.
Is S2 Cognition LLC PCI DSS compliant?
According to S2 Cognition LLC's public trust center, S2 Cognition LLC is PCI DSS compliant. On SOC2C this listing is Listed.
Is S2 Cognition LLC CMMC compliant?
According to S2 Cognition LLC's public trust center, S2 Cognition LLC is CMMC compliant. On SOC2C this listing is Listed.
Is S2 Cognition LLC CSA STAR certified?
According to S2 Cognition LLC's public trust center, S2 Cognition LLC is CSA STAR certified. On SOC2C this listing is Listed.
Is S2 Cognition LLC CCPA compliant?
According to S2 Cognition LLC's public trust center, S2 Cognition LLC is CCPA compliant. On SOC2C this listing is Listed.

Answers published by S2 Cognition LLC

Reproduced from S2 Cognition LLC's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Does S2 Cognition conform with a specific industry-standard security framework?
S2 Cognition's Information Security and Privacy Program establishes policies and controls, monitors compliance with those controls, and proves security and compliance to third-party auditors. The security policies and controls are grounded in the key principles of zero trust, least privilege, need-to-know, and segregation of duties, and govern access to facilities, systems, and data. The policies are refreshed annually, approved by senior management, and reviewed by independent auditors. S2 Cognition's Information Security & Privacy Program has created a security framework based on the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev. 2 (14) control families for the Protection of Controlled Unclassified Information in Non-Federal Information Systems and Organizations as the foundation for the S2 Cognition Information Security policy, standards, and controls. This is also in alignment with the family of (14) domains and controls found in the ISO 27001:2022 Standard and the AICPA SOC 2 Trust Services Criteria. S2 Cognition believes that the implementation of controls should be applied consistently across all areas of the enterprise, iterative, continuously maturing across the dimensions of improved effectiveness, and provide increased auditability and decreased friction.
Where are S2 Cognition's servers located?
S2 Cognition operates within Amazon Web Services (AWS). S2 Cognition leverages AWS components to provide reliable, fault-tolerant, and highly available systems in the cloud. AWS follows the Shared Responsibility Model. AWS is responsible for the security of the cloud, and S2 Cognition is responsible for security in the cloud. S2 Cognition's infrastructure is hosted in US-based AWS data centers housed in state-of-the-art facilities that maintain a highly secure server environment with 24x7 monitoring, surveillance, and support to prevent unauthorized access and ensure data security. Advanced security measures including firewalls, security guards, and surveillance are taken to ensure the continued service and protection of operational data from natural disasters, intruders, and disruptive events. These data centers meet industry standards such as ISO 27001:2022, SOC 2, CSA STAR CCM v4.0, FedRAMP, CMMC, etc. They are rigorously audited annually by third parties. If you are required to review the data center SOC report, you can review the latest AWS SOC 3 Report. Learn more about the AWS North America Regions and Availability Zones.
Does S2 Cognition encrypt sensitive data at rest and in transit?
All datastores with customer data, in addition to S3 buckets, are encrypted at rest using 256-bit Advanced Encryption Standard (AES) encryption. S2 Cognition uses the Amazon Web Services (AWS) Key Management Service (KMS) to enable data at rest encryption across S2 Cognition's products. S2 Cognition uses this for encrypting data within databases (RDS), and data stored within S3. AWS KMS uses the Advanced Encryption Standard (AES) algorithm in Galois/Counter Mode (GCM) with 256-bit secret keys. Data is logically separated and access is granted to authorized users only. S2 Cognition uses Transport Layer Security (TLS) 1.2/1.3 encryption and Hypertext Transfer Protocol Secure (HTTPS) for all data transported through S2 Cognition's network servers. S2 Cognition currently uses Load Balancer and CloudFront Security Policies supporting TLS 1.2 and higher. Details of this can be found here. All connections to S2 Cognition's servers are protected by Secure Sockets Layer (SSL) encryption.
Does S2 Cognition conduct penetration tests and vulnerability scans?
S2 Cognition conducts an independent external penetration test annually and requires vulnerability scanning at key stages of the Secure Development Lifecycle (SDLC). All areas of S2 Cognition's products and cloud infrastructure are in-scope for these assessments. The S2 Cognition information security team performs monthly web application vulnerability scans. These scans are configured to run as authenticated scans. Any vulnerabilities found during these scans or any other vulnerability discovery activities are added to a vulnerability tracking system. There, the vulnerabilities are verified, categorized, and evaluated for actual risk. Vulnerabilities are remediated in accordance with the schedule listed below: The following SLA is followed for vulnerability findings based on a CVSS. Non-CVSS scored vulnerabilities with a risk score are determined by leveraging the OWASP Risk Rating Methodology (Risk = Likelihood \* Impact). - Critical Severity = 30 days - High Severity = 60 days - Medium Severity = Discretionary - Low Severity = Discretionary - Informational Severity = Discretionary If you feel you have discovered a security flaw in our system, you can submit any vulnerabilities by contacting the S2 Cognition information security team directly at [Security@s2cognition.com](mailto:security@s2cognition.com).
Does S2 Cognition have a Bug Bounty Program?
Security Notice – Responsible Disclosure At S2 Cognition, we are committed to protecting the confidentiality, integrity, and availability of our systems and data in accordance with our SOC 2 controls. While we do not currently offer a public bug bounty program, we encourage responsible disclosure of any identified vulnerabilities in our products or services. Your efforts help us maintain a secure and trustworthy environment. To report a potential security issue, please contact us at: [Security@s2cognition.com](mailto:security@s2cognition.com) When reporting, please include: - A clear description of the issue - Steps to reproduce the vulnerability - Any relevant technical details or tools used - Your contact information so we can follow up We will acknowledge your report within three (3) business days and maintain communication throughout our assessment and resolution process. Please do not publicly disclose any vulnerabilities without written permission from S2 Cognition. Responsible disclosure helps us strengthen our controls and reinforces our commitment to SOC 2 compliance. Thank you for supporting the security of our platform.