Honest by architecture, not by certificate.

Coset doesn't hold a SOC 2 report or an ISO certificate yet. This page lists exactly what's built instead, what it's for, how it's verified, and how to reach the person who built it.

Structural properties
4 live
Model training on your data
None
SOC 2
Not yet
ISO 27001
Not yet
What's live today

Not a roadmap. What's actually built.

Four properties that hold structurally, rather than because a policy says so.

No query can cross this line. Enforced by Postgres row-level security inside the database itself, not by application code that a bug could route around.

Isolation enforced at the database

Every workspace's data is separated by Postgres row-level security inside the database itself, not by application checks a bug could route around. Automated guard tests run on every change specifically to confirm one workspace cannot read another's.

Live

Credentials encrypted, not merely protected

QuickBooks OAuth tokens are envelope-encrypted through Azure Key Vault, using RSA-OAEP for the key and AES-256-GCM for the data, with your workspace ID bound into the encryption itself. Rotation is atomic, so there's no window where a stale credential still works.

Live

The agent cannot widen its own permissions

The categorization agent has no write access to the rules it operates under, and every proposal requires a person to confirm it before anything reaches your books. Your ledger and documents answer your questions inside your workspace; they are not used to train any model.

Live

Storage access is scoped, not broad

Cloud storage and queue permissions are scoped to specific containers and roles rather than granted account-wide, with negative-control tests confirming access fails where it should.

Live

What your data actually runs on.

The companies whose infrastructure Coset relies on to operate, and what each one is for. No hidden fourth party gets your data.

CompanyPurposeWhat it can see
Microsoft AzureCloud hosting, storage, and credential encryption (Key Vault)Encrypted data at rest; your QuickBooks credentials only in envelope-encrypted form
AnthropicClaude models, used to read documents and answer questionsThe specific passages sent as context for a given question, not your full ledger
Voyage AIDocument embeddings, used to find the relevant passage for a questionDocument text, for indexing only, not your QuickBooks credentials

None of the above trains a model on your data. This list changes rarely; if it ever does, it's disclosed here before it takes effect.

Questions a diligence review actually asks.

Answered directly, without a badge to point at instead.

Do you use my data to train any model?

No. Your ledger and documents are used to answer your questions and power agents inside your own workspace, not to train Claude, Voyage's models, or any other model.

Is my workspace's data isolated from other customers?

Yes, at the database layer via row-level security, not just in application code. Verified with automated tests specifically designed to confirm one workspace can't read another's data.

Can Coset write to my books without my approval?

No. Every categorization proposal requires human confirmation before it's applied. The categorization agent itself has no write access to the rules it operates under. That's enforced structurally, not just by policy.

How are my QuickBooks credentials stored?

Envelope-encrypted via Azure Key Vault, with your workspace ID bound into the encryption itself, and atomic token rotation so there's no gap where a stale credential is usable.

Do you hold SOC 2, ISO 27001, or similar certifications?

Not yet. Coset is an early-stage product, and formal third-party certification isn't in place. Everything on this page is a structural, testable property of the system today, not a claim awaiting an audit to confirm it.

Found a security issue?

Email security@trycoset.com. It goes directly to the person building this product.

Bring your books somewhere that shows its working.

Request a demo