Skip to content
COSA

Security & trust

Security your compliance team can sign off

Client calls are some of the most sensitive records your firm holds. Here's how COSA protects them — and how it keeps people, not models, accountable for every decision.

Your organisation · security

Protected
Access
Invitation only
Sign-in
Two-factor (TOTP)
Permissions
Admin · Supervisor · User
Data isolation
Row-level security
Transport
HTTPS + HSTS
Activity
Audit logged

ICO registration ZB738672 · Skynet Solutions Ltd

Controls

The protections in place today

No roadmap promises — these are the controls built into the COSA app your team would use.

Invitation-only accounts

Nobody can sign themselves up to your organisation. People join only when one of your admins invites them.

Role-based permissions

Admin, supervisor and user roles decide who can see, change and export what inside your organisation.

Two-factor authentication

Time-based one-time codes from any authenticator app add a second step to every sign-in that enables it.

Isolated by design

Row-level security in the database keeps each firm's calls, clients and results separate from every other firm's.

Encrypted in transit

All traffic is served over HTTPS, with HTTP Strict Transport Security enforced in production.

Hardened in the browser

A content security policy limits where scripts, media and connections can load from, and frame protections guard against clickjacking.

Full audit log

Logins, uploads, exports and overrides are recorded, so activity can be traced to a named user and a time.

Scoped, revocable API keys

Integration keys are limited to the data they need, and an admin can revoke one the moment it's no longer used.

Data journey

How a call moves through COSA

From the moment a call ends to the evidence in your file — every step is controlled, attributable and reviewable.

  1. 01

    The call ends

    Aircall sends the finished recording, or your team uploads it. COSA never joins or interrupts a live call.

  2. 02

    It's transcribed

    Speech becomes a timestamped transcript your reviewers can search and jump through.

  3. 03

    It's assessed

    Every rule that applies to the call type is checked, with the quote, the reasoning and a confidence score.

  4. 04

    Your team reviews

    Reviewers confirm or override flagged results. Overrides are logged and the original verdict is kept.

  5. 05

    It's evidenced

    Reports and client packs are exported on demand, and every export is written to the audit log.

Responsible AI

AI that shows its working

A compliance decision you can't explain is a liability. COSA is built so every result can be checked, challenged and traced back to the call.

Your rules, your standards

COSA checks calls against the rules your compliance team writes — not a generic template it can't explain.

Evidence with every verdict

Each result carries the quoted words, a written explanation and a confidence score, so it can be checked in seconds.

People have the final say

Authorised reviewers can override any result. The original verdict stays on record for the audit trail.

Coverage you can prove

Every in-scope call is assessed, and every call you exclude is logged with the reason. No unexplained gaps.

Assessments
1,284
last 30 days
Compliance rate
91%
↗ 4 pp vs prior
Needs review
37
3% of calls

1 result on this check was manually overridden by an authorised reviewer. The original verdict is retained for audit purposes.

Client Pack · Margaret Hughes

Every report, transcript and summary in one ZIP

Prepare pack
  • compliance/
  • transcriptions/
  • summaries/

Supplier due diligence

Onboarding a new supplier? We'll make it straightforward

Your risk and compliance teams will have questions before COSA goes near a client call. Send them our way — we'll walk through the detail with the people who need it.

Topics we cover in a security review

  • User access, roles and two-factor authentication
  • How each firm's data is isolated
  • What the audit log records
  • Integrations, API keys and data flows
  • How AI verdicts are produced, checked and overridden
  • Data retention and deletion
  • Company and ICO registration details

The company behind COSA

Legal entity
Skynet Solutions Ltd, trading as COSA AI
Company number
15086136 (England & Wales)
Registered office
25-29 Sandy Way, Yeadon, Leeds LS19 7EW
ICO registration
ZB738672

FAQ

Security questions we're asked most

No. COSA only processes a call once it has finished — it can't make, join or interrupt one. Your advisers keep working exactly as they do today.

Only people your admins have invited to your organisation, within the permissions of their role. Each firm's data is isolated at the database level, so it is never visible to another firm.

Every verdict comes with a written explanation, the quoted evidence from the transcript and a confidence score, so a reviewer can check it in seconds. COSA supports your team's judgement rather than replacing it: authorised reviewers can override any result, and the original verdict is kept for the audit trail.

Yes. Logins, uploads, exports and overrides are recorded in an audit log, so you can show who did what, and when. Overridden results keep their original verdict.

Accounts are invitation-only, with role-based permissions and two-factor authentication. Each firm's data is isolated at the database level, data is encrypted in transit, and logins, exports and changes are written to an audit log. COSA is operated by Skynet Solutions Ltd, registered with the ICO (ZB738672).

Bring your security questions to the demo

See the controls for yourself — user management, two-factor sign-in, overrides and the audit trail — on a walkthrough tailored to your firm.

  • Tailored to your call types
  • No obligation
  • Reply within 24 hours