Security & trust
Security your compliance team can sign off
Your organisation · security
Protected- Access
- Invitation only
- Sign-in
- Two-factor (TOTP)
- Permissions
- Admin · Supervisor · User
- Data isolation
- Row-level security
- Transport
- HTTPS + HSTS
- Activity
- Audit logged
ICO registration ZB738672 · Skynet Solutions Ltd
Controls
The protections in place today
No roadmap promises — these are the controls built into the COSA app your team would use.
Invitation-only accounts
Nobody can sign themselves up to your organisation. People join only when one of your admins invites them.
Role-based permissions
Admin, supervisor and user roles decide who can see, change and export what inside your organisation.
Two-factor authentication
Time-based one-time codes from any authenticator app add a second step to every sign-in that enables it.
Isolated by design
Row-level security in the database keeps each firm's calls, clients and results separate from every other firm's.
Encrypted in transit
All traffic is served over HTTPS, with HTTP Strict Transport Security enforced in production.
Hardened in the browser
A content security policy limits where scripts, media and connections can load from, and frame protections guard against clickjacking.
Full audit log
Logins, uploads, exports and overrides are recorded, so activity can be traced to a named user and a time.
Scoped, revocable API keys
Integration keys are limited to the data they need, and an admin can revoke one the moment it's no longer used.
Data journey
How a call moves through COSA
From the moment a call ends to the evidence in your file — every step is controlled, attributable and reviewable.
- 01
The call ends
Aircall sends the finished recording, or your team uploads it. COSA never joins or interrupts a live call.
- 02
It's transcribed
Speech becomes a timestamped transcript your reviewers can search and jump through.
- 03
It's assessed
Every rule that applies to the call type is checked, with the quote, the reasoning and a confidence score.
- 04
Your team reviews
Reviewers confirm or override flagged results. Overrides are logged and the original verdict is kept.
- 05
It's evidenced
Reports and client packs are exported on demand, and every export is written to the audit log.
Responsible AI
AI that shows its working
A compliance decision you can't explain is a liability. COSA is built so every result can be checked, challenged and traced back to the call.
Your rules, your standards
COSA checks calls against the rules your compliance team writes — not a generic template it can't explain.
Evidence with every verdict
Each result carries the quoted words, a written explanation and a confidence score, so it can be checked in seconds.
People have the final say
Authorised reviewers can override any result. The original verdict stays on record for the audit trail.
Coverage you can prove
Every in-scope call is assessed, and every call you exclude is logged with the reason. No unexplained gaps.
- Assessments
- 1,284
- last 30 days
- Compliance rate
- 91%
- ↗ 4 pp vs prior
- Needs review
- 37
- 3% of calls
1 result on this check was manually overridden by an authorised reviewer. The original verdict is retained for audit purposes.
Client Pack · Margaret Hughes
Every report, transcript and summary in one ZIP
- compliance/
- transcriptions/
- summaries/
Supplier due diligence
Onboarding a new supplier? We'll make it straightforward
Your risk and compliance teams will have questions before COSA goes near a client call. Send them our way — we'll walk through the detail with the people who need it.
Topics we cover in a security review
- User access, roles and two-factor authentication
- How each firm's data is isolated
- What the audit log records
- Integrations, API keys and data flows
- How AI verdicts are produced, checked and overridden
- Data retention and deletion
- Company and ICO registration details
The company behind COSA
- Legal entity
- Skynet Solutions Ltd, trading as COSA AI
- Company number
- 15086136 (England & Wales)
- Registered office
- 25-29 Sandy Way, Yeadon, Leeds LS19 7EW
- ICO registration
- ZB738672
FAQ
Security questions we're asked most
No. COSA only processes a call once it has finished — it can't make, join or interrupt one. Your advisers keep working exactly as they do today.
Only people your admins have invited to your organisation, within the permissions of their role. Each firm's data is isolated at the database level, so it is never visible to another firm.
Every verdict comes with a written explanation, the quoted evidence from the transcript and a confidence score, so a reviewer can check it in seconds. COSA supports your team's judgement rather than replacing it: authorised reviewers can override any result, and the original verdict is kept for the audit trail.
Yes. Logins, uploads, exports and overrides are recorded in an audit log, so you can show who did what, and when. Overridden results keep their original verdict.
Accounts are invitation-only, with role-based permissions and two-factor authentication. Each firm's data is isolated at the database level, data is encrypted in transit, and logins, exports and changes are written to an audit log. COSA is operated by Skynet Solutions Ltd, registered with the ICO (ZB738672).
Bring your security questions to the demo
See the controls for yourself — user management, two-factor sign-in, overrides and the audit trail — on a walkthrough tailored to your firm.
- Tailored to your call types
- No obligation
- Reply within 24 hours
