Cobrainer Trust Center

The purpose of this Trust Center is to provide customers, stakeholders, and regulators with a clear and accurate overview of the information related to security, privacy and infrastructure practices at Cobrainer, and how AI is used within the Cobrainer platform, how associated risks are identified and managed, and how legal and ethical requirements are addressed. It will be continuously reviewed and updated to reflect technological developments, regulatory changes, and evolving best practices in the use of AI in human resources. Report an incident: [support@cobrainer.com](mailto:support@cobrainer.com "support@cobrainer.com") Report a vulnerability: [security@cobrainer.com](mailto:security@cobrainer.com "security@cobrainer.com") For data privacy requests: [privacy@cobrainer.com](mailto:privacy@cobrainer.com "privacy@cobrainer.com") Cobrainer's security, compliance and privacy efforts are lead by: **Fabian Dziamski** (Legal and Compliance) — **Anton Zering** (IT Security) — **Sarath Kumar Kondreddi** (AI & Innovation) — **Sven Hunzinger** (Data Privacy)

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Cobrainer Trust Center

Cobrainer Trust Center

The purpose of this Trust Center is to provide customers, stakeholders, and regulators with a clear and accurate overview of the information related to security, privacy and infrastructure practices at Cobrainer, and how AI is used within the Cobrainer platform, how associated risks are identified and managed, and how legal and ethical requirements are addressed. It will be continuously reviewed and updated to reflect technological developments, regulatory changes, and evolving best practices in the use of AI in human resources.

Report an incident: support@cobrainer.com

Report a vulnerability: security@cobrainer.com

For data privacy requests: privacy@cobrainer.com

Cobrainer's security, compliance and privacy efforts are lead by: Fabian Dziamski (Legal and Compliance) — Anton Zering (IT Security) — Sarath Kumar Kondreddi (AI & Innovation) — Sven Hunzinger (Data Privacy)

security@cobrainer.com

Compliance and certifications

Independent attestations and formal programs demonstrate alignment with leading security and privacy standards.

ISO 27001:2022 certification

An accredited body certified the information security management system, validating controls across people, process and technology.

GDPR and CCPA alignment

Platform design, contracts and operational processes adhere to major privacy laws, giving customers a ready foundation for global compliance.

EU AI Act readiness

AI functions are classified and managed as high-risk employment systems, positioning customers for forthcoming regulatory duties.

TISAX assessment result

The platform achieved a TISAX rating for information with very high protection needs, recognised by automotive industry partners.

EU AI Act provider compliance

Cobrainer fulfils provider obligations for high-risk employment AI systems, including transparency, risk management and human oversight measures.

EU artificial intelligence act alignment

AI features are designed as decision-support tools with human oversight to satisfy high-risk system obligations under the draft act.

GDPR processor support

Documented guidance and direct assistance help customers complete DPIAs and meet Article 28 obligations.

Continuous regulatory monitoring

Legal and compliance teams track global HR-AI regulations and update controls as requirements evolve.

Shared responsibility model

A clearly defined split between provider and customer duties clarifies who manages which controls, streamlining compliance assessments.

SOC 2 type II audit

Management commits to delivering an externally audited SOC 2 type II report to customers for continuous assurance.

Audit readiness documentation

Comprehensive artefacts covering security, privacy and AI governance are maintained to support customer due diligence and regulatory audits.

TÜV SÜD API penetration certificate

An independent TÜV SÜD assessment reported zero exploitable vulnerabilities in the public APIs.

Customer audit support

Documentation and access to assurance materials are provided to help customers complete their own audits and risk assessments.

Ongoing regulatory monitoring

Dedicated processes track legal developments and update controls so that the platform stays aligned with evolving standards and legislation.

Security testing and assessment

Regular independent security assessments verify the effectiveness of technical safeguards and keep vulnerabilities out of production.

Lifecycle testing of AI features

Skills classification, content generation and other AI functions undergo testing before release and during updates.

Independent penetration testing

A respected external security firm conducts annual penetration tests on the production environment, confirming there were no critical, high, medium or low findings in the latest assessment.

Lifecycle-integrated testing

Functional, security and data handling tests are executed before each release and during updates to catch issues early.

Internal penetration testing cycles

Engineering teams run additional penetration tests during each development cycle to uncover issues earlier and reinforce secure coding standards.

Internal quality and risk reviews

Dedicated reviews evaluate model behaviour, edge cases and potential HR risks, ensuring outputs remain suitable for employment contexts.

Continuous assurance program

Testing and risk assessments are treated as ongoing tasks, keeping controls effective as the product evolves.

External assurance reviews

Cobrainer considers assurance reports from infrastructure and service partners to verify that upstream controls meet required standards.

Third-party vulnerability scanning

A qualified vendor performs semi-annual vulnerability scans across infrastructure and applications, generating risk-ranked reports and remediation guidance.

Continuous assurance programme

Testing and assurance are treated as ongoing disciplines rather than one-time events, providing sustained confidence over the product’s life.

Static application security testing

Automated SAST tools are integrated into the CI pipeline to identify insecure code patterns before changes are merged.

External provider assurance

Results from third-party audits and certifications are factored into the platform’s overall assurance posture.

Controlled model updates with validation

New model versions are introduced only after they meet defined quality expectations and stability checks.

Dependency and container scanning

Every build automatically scans open-source libraries, container images and infrastructure code for known CVEs and configuration weaknesses.

Audit documentation support

Up-to-date evidence packs help customers satisfy their own auditors without extensive additional work.

Data protection

Comprehensive encryption, secret management and lifecycle controls safeguard customer data throughout its journey.

Data segregation and tenant isolation

Customer data is logically separated so that job structures, skill extensions and configurations are never shared across tenants, eliminating cross-customer data leakage.

Purpose limitation and minimization

Processing is restricted to data strictly necessary for HR use cases, lowering the attack surface and compliance burden.

Encryption at rest

All stored customer data is protected with AES-256 encryption managed by AWS Key Management Service.

Processor role under customer instruction

Cobrainer processes personal data solely on documented customer instructions, maintaining the customer’s status as data controller.

Customer-defined data retention policies

Organizations set retention schedules while the platform enforces them, aligning storage with legal requirements.

Data protection by design and default

Privacy principles such as purpose limitation, data minimisation and access control are embedded into product architecture from the outset, ensuring lawful processing without retrofitting.

Encryption in transit

TLS 1.2 or higher secures every connection between the platform, integrations and end-user browsers.

Data minimisation

Processing is limited to the information strictly required for configured HR use cases, reducing exposure of unnecessary personal data.

Contractual GDPR and CCPA alignment

Platform operations and terms are structured to support compliance with European and Californian privacy regulations.

EU data residency

Production workloads and backups remain solely in the AWS Frankfurt region, keeping data inside the European Union.

Aggregated and anonymized analytics

Only non-identifiable data is used to enhance platform capabilities, avoiding exposure of customer-specific information.

No cross-customer data reuse

Customer job structures and skill extensions remain isolated and are not shared with other tenants.

Retention and deletion controls

The platform provides mechanisms to delete or anonymise data on customer instruction and never stores personal information longer than contractually agreed.

Secret management with automated rotation

Application credentials are stored in AWS Secrets Manager, accessed through role-based policies and rotated on a scheduled or on-demand basis.

Retention aligned with customer policies

Personal data is kept only as long as required for agreed services and legal obligations, after which it can be deleted or anonymised.

Data deletion controls

Data subjects and client administrators can trigger irreversible deletion of personal data, with actions logged and reported back to the controller.

International data transfer safeguards

When transfers outside the EU/EEA are necessary, recognised legal mechanisms and contractual protections are applied to maintain compliance with data protection laws.

Infrastructure security

Layered cloud controls protect the hosting environment against network, system and availability threats.

Secure SaaS architecture

Security is integrated across the system design to protect against unauthorized access, data loss and misuse.

Security by design and operation

End-to-end security controls are embedded across the system architecture to guard against unauthorised access, data loss and misuse.

Security by design for SaaS platform

The service is engineered with layered controls to protect confidentiality, integrity and availability of HR data.

AWS region isolation

All production services run in the AWS eu-central-1 region, leveraging three availability zones for resilience.

Tenant isolation and data segregation

Logical separation prevents one customer’s data from being accessed by another, preserving confidentiality.

VPC network segmentation

Separate public, private and database subnets confine traffic flows and minimise exposure surfaces.

Controlled integration interfaces

Connections to external HR systems use restricted channels and scoped data exchange, limiting exposure to third-party risks.

Security of integrations

Connections to external HR systems use controlled interfaces and limited data scopes, reducing integration attack surfaces.

Private subnets for databases

Databases reside in non-routable subnets, accepting connections only from approved application services.

Organisational security measures

Internal role separation and access restrictions safeguard operational environments and reinforce accountability.

Protected HR system integrations

Data exchanged with external systems such as SAP SuccessFactors and Workday flows through controlled, security-checked interfaces.

Multi-availability zone redundancy

Workloads are deployed across multiple AZs to survive data-centre failures without customer impact.

Preventive and detective monitoring

Continuous observation of infrastructure detects anomalies early, helping avert service disruptions and security breaches.

Defense-in-depth firewall rules

Security groups default to deny-all and explicitly allow only required ports between tiers and to the internet.

Product Security

Security is baked into the software development life cycle to prevent defects from reaching customers.

Secure development lifecycle

Security requirements and threat modelling are embedded in agile sprints from design through deployment.

Security by design integration

Engineering teams embed security considerations throughout product development, lowering inherent risk.

Explicit user invocation of AI actions

AI tasks run only when triggered by a clear UI action, eliminating hidden processing.

Quality checks on AI outputs

Generated classifications and content undergo validation to confirm accuracy and suitability for HR use cases.

Review and edit capability for AI outputs

Suggested job structures, skills or content can be accepted, modified or rejected before they affect organisational data.

Automated CI/CD security gates

Build pipelines block releases that fail security scans, ensuring only compliant code reaches production.

Transparency and explainability features

Contextual information is provided to help users understand AI suggestions, fostering trust and accountability.

Safeguards against automation bias

Design emphasises reviewability and user control to avoid over-reliance on algorithmic recommendations.

Peer code reviews

Every change is reviewed and approved by qualified engineers, adding human oversight to automated checks.

User review and override capability

Customers can edit or reject AI-generated results before adoption, preventing unintended impacts.

Environment segregation

Dedicated development, staging and production accounts prevent cross-environment impact and enable safer testing.

Customer configuration control

Organisations decide which AI features to enable and how outputs are adopted, aligning use with internal policies.

Secure session management

The application enforces modern cookie settings and session controls to mitigate hijacking risks.

Access control

Robust authentication and authorization mechanisms ensure only the right people obtain the right level of access.

Single sign-on integration

The platform supports SAML, OAuth and OpenID Connect so customers can enforce their own identity provider policies.

Role-based access control

Permissions are assigned to roles so that each user only sees and performs actions that fit their responsibilities, reducing the likelihood of unauthorized data exposure or configuration changes.

Role-based access controls

Platform permissions are assigned to roles so that users only see data and functions aligned with their responsibilities.

Customer-defined user permissions

Customers can create and manage their own roles and permission sets, allowing them to align platform access with internal governance and segregation-of-duties requirements.

Customer-defined permission management

Administrators can configure and tailor access rights to match internal governance requirements, ensuring the platform aligns with segregation-of-duties policies.

Customer-defined permission sets

Administrators can tailor roles and entitlements to match internal governance and segregation-of-duties requirements.

Administrative action restrictions

High-impact tasks such as configuration changes and AI feature management are limited to designated administrative roles, preventing accidental or malicious alterations.

Multi-factor authentication

All internal services and tools require MFA, adding a second verification step beyond passwords.

Feature-level AI enablement

Organisations may enable or disable specific AI capabilities per role, ensuring that only authorised users can invoke automated assistance.

Restricted administrative actions

High-impact configuration changes and AI feature management are limited to designated roles, preventing accidental or malicious alterations.

Explicit AI invocation controls

AI features operate only when a user deliberately triggers them in the interface, keeping automated processing under continuous human oversight.

Token-based VPN access

Employees who connect remotely must authenticate with hardware or software tokens in addition to credentials.

User-triggered AI operations

AI functions activate only after an explicit user action in the interface, guaranteeing human oversight for every AI-supported task.

Access provisioning and de-provisioning workflow

User accounts are created, reviewed and removed via an HR-linked process that includes quarterly manager attestations.

Internal access restrictions

Cobrainer employees follow strict internal access limitations and role separation when developing and operating the platform, safeguarding customer environments from insider risk.

AI governance

Dedicated oversight assures fairness, transparency and controlled lifecycle management of AI models.

Cross-functional governance structure

Product, engineering, security and legal teams jointly oversee AI features, embedding accountability into every lifecycle stage.

Cross-functional AI governance structure

Product, engineering, security and legal stakeholders jointly review and approve AI system changes for risk and compliance impact.

Governance structure and oversight

Cross-functional committees oversee AI design, deployment and retirement, embedding accountability across the organisation.

Lifecycle accountability

Decisions on model updates and safeguards undergo documented review to assess legal, ethical and operational impacts.

Accountability in the AI lifecycle

Clear owners are assigned for every AI change, covering technical performance, legal compliance and user impact.

Internal awareness and enablement

Staff involved in AI receive role-specific guidance on legal obligations and platform limitations, reducing the risk of misguided development.

Fairness and bias mitigation focus

Skills-based representations and human review are used to reduce reliance on biased proxies and support equitable outcomes.

Risk identification and escalation

Structured pathways allow emerging AI risks to be raised and resolved before they affect customers.

Continuous model lifecycle management

Models are versioned, monitored and updated using curated datasets, keeping outputs accurate as skill landscapes evolve.

Human oversight principle

The platform deliberately prevents fully autonomous employment decisions, requiring humans to review and approve AI suggestions.

Periodic AI risk management review

Regular reassessments verify that controls stay effective as technology, regulation and customer use cases evolve.

Third-party management

Formal oversight of vendors and subprocessors keeps the supply chain secure and compliant.

Periodic review of third-party LLMs

Suitability and risk profiles of external language models are reassessed to maintain security and compliance alignment.

Data processing agreements

Contractual DPAs with AWS and Mixpanel impose GDPR-aligned security, privacy and audit obligations.

Third-party LLM suitability assessments

Large language model providers are selected against criteria for quality, latency and regional deployment, ensuring safe content generation.

Periodic risk review of AI providers

Third-party large language models undergo suitability assessments to confirm ongoing legal and security compliance.

EU hosting by AWS

Cloud infrastructure is provisioned in Frankfurt, ensuring subcontractor storage stays within the EU.

Minimal data sharing with external models

Only information required for a requested task is transmitted, limiting exposure when leveraging external AI services.

Periodic third-party risk reviews

The risk profile of external models is re-evaluated over time to maintain alignment with legal, security and performance expectations.

EU event data hosting by Mixpanel

Telemetry is processed only in the Netherlands data centre under an agreed GDPR DPA.

Subprocessor transparency on request

A current list of external models and service providers is available to customers via the security contact.

External assurance consideration

Assurance reports from infrastructure and service partners are incorporated into overall risk management to validate upstream controls.

Secure data exchange with HR systems

Data shared with platforms like SAP or Workday is limited to necessary fields and transmitted through protected interfaces, minimising exposure.

Subprocessor security reviews

Cobrainer evaluates and documents the security posture of each subprocessor as part of onboarding and renewal.

External assurance integration

Third-party audit reports and certifications are factored into overall platform risk management.

Customer-controlled system connections

Organizations decide which HR systems to connect and what data flows, retaining authority over third-party integrations.

API security hardening roadmap

The platform’s APIs incorporate strong controls to defend against misuse and abuse.

Endpoint authorization checks

Every API call is evaluated against the caller’s role before execution, blocking unauthorised actions.

Rate limiting enforcement

Configured thresholds throttle excessive requests, reducing the impact of brute-force or model-stealing attempts.

Client credential authentication

Integrations authenticate with unique client IDs and certificates stored securely in Secrets Manager.

Input validation and sanitization

Server-side routines cleanse and validate all incoming data to prevent injection and deserialization attacks.

Monitoring and logging

Continuous telemetry and analytics provide real-time insight and early warning of security issues.

Real-time application monitoring

Datadog and AWS CloudWatch track performance, errors and capacity to spot anomalies quickly.

Security event monitoring

The platform is continuously observed for events that could indicate compromise or misuse, enabling swift intervention.

Continuous platform monitoring

Telemetry is analysed to spot security-relevant events and abnormal behaviour across the service.

Continuous security event monitoring

The platform observes operational metrics and logs to spot suspicious activity that could indicate compromise.

Anomaly detection

Detective controls flag unusual behaviour patterns that may signal threats before they escalate.

Preventive and detective measures

Automated safeguards help stop unauthorised access while alerting teams to potential threats.

Anomaly detection mechanisms

Automated checks identify unusual behavior patterns, enabling rapid investigation and response.

SIEM integration

GuardDuty, CloudTrail and third-party SIEM tools correlate logs for threat detection across the stack.

Centralised audit logging

Administrative actions and API calls are immutably recorded for forensic and compliance purposes.

Preventive controls enforcement

Monitoring data feeds into preventive measures that block unauthorized actions before they escalate.

Incident detection for anomalous AI behaviour

Monitoring extends to AI outputs so unexpected results can be flagged for investigation.

Preventive and detective safeguards

Combined monitoring and prevention measures reduce the likelihood of unauthorised access and improve response accuracy.

Automated anomaly alerts

Deviation thresholds trigger instant notifications to on-call engineers and security staff.

Documented escalation workflows

Alerts route through defined channels to ensure timely investigation by responsible personnel.

Access log retention

Security event and access logs are stored for at least one year, supporting investigations and audits.

Employee security

People-centric safeguards reduce insider and social engineering risks.

Security awareness training

Team members receive guidance on secure development and data handling practices, reducing human-related risks.

Security awareness practices for personnel

Employees involved in platform development and operations receive training to recognise and mitigate threats.

Internal role separation

Access to production systems is limited and segregated, preventing concentration of sensitive privileges.

Annual policy acknowledgement

Employees must reaffirm understanding of security and ethics policies every year.

Pre-employment reference checks

HR verifies candidate backgrounds and references before granting access to sensitive systems.

Assigned security responsibilities

Clearly defined ownership enables swift escalation and accountability for security matters.

Clean desk policy

Random inspections enforce the removal of sensitive materials from workspaces after hours.

Quarterly role access reviews

Managers validate that permissions for their team members remain appropriate for current duties.

Privacy and user rights

Built-in features empower data subjects and controllers to meet GDPR obligations effortlessly.

Data subject rights support

Functions allow access, rectification, deletion and portability requests to be fulfilled within legal timeframes.

Consent management workflow

New users must actively accept a client-controlled consent statement before accessing the service.

Data subject rights enablement

Built-in functions support access, rectification, deletion and portability requests, helping customers comply with privacy laws.

Data protection by design and default

Platform features incorporate purpose limitation and data minimization principles from the outset, lowering exposure of personal data.

Employee opt-out capability

Individuals can disable employee-facing features when allowed by company policy, supporting transparency and voluntary participation.

In-app privacy policy access

The latest privacy policy is always reachable from onboarding screens and account settings.

Employee opt-out and transparency features

Where enabled, individuals can view their data and opt out of specific features, fostering trust and legal compliance.

User data export

Individuals can download a comprehensive PDF report of their stored personal data at any time.

Support for data subject rights

Customers can access, export, rectify or delete personal data through native tooling, streamlining compliance with legal requests.

Controller-processor role clarity

Contractual and technical measures ensure customers remain data controllers while Cobrainer processes data strictly under instruction.

Transparency to affected individuals

The platform helps customers inform employees about AI usage and the role of human decision-makers.

International data transfer safeguards

Recognised mechanisms and contractual protections secure any personal data moved outside the EEA.

Customer governance alignment tools

Configuration options let organisations tailor transparency notices and approval flows to match internal policies and works-council agreements.

Retention and deletion mechanisms

Personal data is stored only as long as required for contracted services, with tools that permit scheduled or on-demand deletion.

Profile visibility settings

Users decide whether their information is seen by all employees, recruiters, managers or talent developers.

International transfer safeguards

Cross-border data flows rely on recognized legal mechanisms and contractual protections, maintaining privacy compliance worldwide.

Self-service account deletion

Users can permanently delete their account and associated data without contacting support.

Incident response

A formal plan and automated alerts enable rapid detection, containment and communication of security events.

Documented incident response plan

Clear procedures define roles and steps for identify, contain, eradicate, recover and review phases.

Customer incident reporting channel

Dedicated mechanisms allow customers to report suspected security or AI issues directly to the response team.

Dedicated reporting channels

Customers can promptly report suspected incidents through defined contact points, accelerating triage and containment.

Customer incident reporting channels

Customers can report suspected incidents through defined contact paths, ensuring rapid engagement with the response team.

Structured severity assessment

All reported events are triaged to determine scope, impact and required containment actions.

Structured assessment and response

Every report is triaged to determine severity and scope, with containment and remediation steps executed according to predefined playbooks.

Automated alerting workflows

Monitoring tools instantly notify the security team of anomalies in metrics, logs or threat feeds.

Timely customer notifications

Affected organizations receive incident updates in compliance with contractual and legal requirements, aiding coordinated response.

Stakeholder communication procedures

Customers, regulators and law enforcement are informed promptly and transparently when applicable.

Timely customer communication

Affected customers receive prompt notifications and status updates in line with contractual and legal obligations, enabling them to meet their own disclosure duties.

Post-incident root cause analysis

Lessons learned feed back into technical safeguards and processes to reduce likelihood of recurrence.

Post-incident reviews

Each incident triggers a lessons-learned session to refine controls and prevent recurrence.

Post-incident remediation and lessons learned

Root-cause analysis drives corrective actions and process improvements, strengthening defences against future events.

Post-incident remediation

Root causes are analyzed and corrective measures implemented to prevent recurrence and strengthen the control environment.

Unified AI incident handling

AI-specific anomalies follow the same rigorous process, ensuring consistent governance regardless of incident source.

AI-specific issue handling

The same framework addresses unexpected AI outputs or limitations, allowing model adjustments or configuration changes when needed.

Continuous improvement cycle

Findings feed back into risk management, updating policies, playbooks and training.

Business continuity

Redundant design and backup processes maintain availability and protect data from loss.

Automated database backups

Critical data stores are backed up on a scheduled basis with validated restoration procedures.

Controlled deployment process

Model and software updates are rolled out in a managed manner to maintain platform stability for customers.

Continuous lifecycle management

Ongoing monitoring and adjustment of models ensure reliable functionality as organizational contexts change.

Disaster recovery policy

Documented RTO/RPO targets and recovery steps guide teams during major service interruptions.

Availability monitoring

Infrastructure health checks detect issues early, supporting rapid remediation and minimizing downtime.

Comprehensive backup strategy

Configurations, code and infrastructure states are regularly saved to isolated storage for rapid rebuilds.

High availability architecture

Services are distributed across multiple zones so that single-site failures do not disrupt customers.