Cobrainer Trust Center Trust Center

The purpose of this Trust Center is to provide customers, stakeholders, and regulators with a clear and accurate overview of the information related to security, privacy and infrastructure practices at Cobrainer, and how AI is used within the Cobrainer platform, how associated risks are identified and managed, and how legal and ethical requirements are addressed. It will be continuously reviewed and updated to reflect technological developments, regulatory changes, and evolving best practices in the use of AI in human resources. Report an incident: [support@cobrainer.com](mailto:support@cobrainer.com "support@cobrainer.com") Report a vulnerability: [security@cobrainer.com](mailto:security@cobrainer.com "security@cobrainer.com") For data privacy requests: [privacy@cobrainer.com](mailto:privacy@cobrainer.com "privacy@cobrainer.com") Cobrainer's security, compliance and privacy efforts are lead by: **Fabian Dziamski** (Legal and Compliance) — **Anton Zering** (IT Security) — **Sarath Kumar Kondreddi** (AI & Innovation) — **Sven Hunzinger** (Data Privacy)

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Cobrainer Trust Center

Cobrainer Trust Center

The purpose of this Trust Center is to provide customers, stakeholders, and regulators with a clear and accurate overview of the information related to security, privacy and infrastructure practices at Cobrainer, and how AI is used within the Cobrainer platform, how associated risks are identified and managed, and how legal and ethical requirements are addressed. It will be continuously reviewed and updated to reflect technological developments, regulatory changes, and evolving best practices in the use of AI in human resources.

Report an incident: support@cobrainer.com

Report a vulnerability: security@cobrainer.com

For data privacy requests: privacy@cobrainer.com

Cobrainer's security, compliance and privacy efforts are lead by: Fabian Dziamski (Legal and Compliance) — Anton Zering (IT Security) — Sarath Kumar Kondreddi (AI & Innovation) — Sven Hunzinger (Data Privacy)

security@cobrainer.com

Documentation

Featured

SAP_SFSF-SKILLS_Certificate_Cobrainer_26116
SAP_IS-PI-CNT_Cobrainer_Certificate_25969

Subprocessors

Amazon Web Services
Amazon Web Services · EU
Infrastructure Hosting
Datadog
Datadog · EU
Logging and Monitoring
ElevenLabs
ElevenLabs · EU, US
GitLab
GitLab · US
Software Development
Google
Google · EU
Infrastructure Hosting

Controls

Compliance and certifications

Independent attestations and formal programs demonstrate alignment with leading security and privacy standards.

ISO 27001:2022 certification
GDPR and CCPA alignment
EU AI Act readiness
TISAX assessment result
EU AI Act provider compliance
EU artificial intelligence act alignment
GDPR processor support
Continuous regulatory monitoring
Shared responsibility model
SOC 2 type II audit
Audit readiness documentation
TÜV SÜD API penetration certificate
Customer audit support
Ongoing regulatory monitoring
Security testing and assessment

Regular independent security assessments verify the effectiveness of technical safeguards and keep vulnerabilities out of production.

Lifecycle testing of AI features
Independent penetration testing
Lifecycle-integrated testing
Internal penetration testing cycles
Internal quality and risk reviews
Continuous assurance program
External assurance reviews
Third-party vulnerability scanning
Continuous assurance programme
Static application security testing
External provider assurance
Controlled model updates with validation
Dependency and container scanning
Audit documentation support
Data protection

Comprehensive encryption, secret management and lifecycle controls safeguard customer data throughout its journey.

Data segregation and tenant isolation
Purpose limitation and minimization
Encryption at rest
Processor role under customer instruction
Customer-defined data retention policies
Data protection by design and default
Encryption in transit
Data minimisation
Contractual GDPR and CCPA alignment
EU data residency
Aggregated and anonymized analytics
No cross-customer data reuse
Retention and deletion controls
Secret management with automated rotation
Retention aligned with customer policies
Data deletion controls
International data transfer safeguards

Frequently asked security questions

Is Cobrainer secure?

Cobrainer operates this public trust center. It publishes 5 independent compliance certifications, security documentation available on request, and a published list of its subprocessors.

Does Cobrainer have ISO 27001 certification?

Yes. Cobrainer is ISO 27001 certified. You can review this certification in the compliance section of this trust center.

Is Cobrainer GDPR compliant?

Yes. Cobrainer maintains GDPR compliance. See the compliance section of this trust center for details.

Who are Cobrainer's subprocessors?

Cobrainer discloses its subprocessors in this trust center, including amazonwebservices.com, Datadog, and ElevenLabs. See the subprocessors section for the complete list.

How do I request Cobrainer's security documentation?

You can request access to Cobrainer's security documentation directly through this trust center. Submit an access request and the Cobrainer team reviews and grants access.