Skip to main content

Help us improve the Digital Marketplace - send your feedback

COGNA LTD

Cogna Platform

Cogna Platform for hosting and deploying AI-enabled software

Features

  • AI-assisted application configuration in weeks, not months
  • Integrates with existing systems: SAP, databases, APIs
  • Interactive dashboards with real-time data visualisation
  • Geospatial mapping and location-based operational features
  • Role-based permissions control access
  • AI Synthesis supports app development and deployment
  • Application Unit pricing structure

Benefits

  • Deploy operational solutions in weeks instead of years
  • Applications evolve continuously with your changing needs
  • Connects easily with your existing enterprise systems and databases
  • Modern cloud architecture scales to meet demand efficiently
  • Expert guidance throughout discovery, design, and deployment phases
  • Solutions Strategist available to support development and deployment
  • Cogna's Discover, Define, Deliver process enables rapid development

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at finance@cogna.co. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 0 5 9 9 2 3 2 9 2 1 0 9 1 5

Contact

COGNA LTD Craig Moore
Telephone: 07920523668
Email: finance@cogna.co

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI life cycle

  • AI Build Software

AI software services

  • Generative AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Web-based applications requiring internet connectivity
  • Browser compatibility required (modern web browsers)

User support

Email or online ticketing support
Yes
Support response times
Varying response time depending on severity
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Testing performed by web chat supplier (Intercom)
Onsite support
Yes
Support levels
Cogna provides a multi-layered support model with Solutions Strategists at the center, supported by technical support teams:

- In-application support interface (Intercom integration)
- Email support and ticketing system
- Telephone support during Normal Working Hours
- Dedicated Solutions Strategist relationship for each customer

- Application hosting and infrastructure management
- Defect resolution with severity-based prioritization
- Platform maintenance and security updates
- Reasonable change requests to extend functionality
- Continuous iteration to ensure applications remain useful

Full details on SLA tiers and pricing are listed in the price document.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Onsite & online training is provided, along with documentation as needed
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data can be extract on demand from some applications (via CSV download), and in other cases we will work with the customer to provide secure extracts of data as required.
End-of-contract process
Data extract is included
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is provided in plain text format and written in simple to understand text

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
App rendering will vary and not all features will be available
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Data ingest / egress
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
App functionality & interface within the platform

Scaling

Independence of resources
The platform scales vertically and elastically to maintain reliability as workloads grow.
Adaptive capacity: Compute and storage resources scale automatically based on demand and monitored utilisation.
Performance assurance: Continuous monitoring and periodic stress testing sustain fast response times under load.
Dedicated tenancy: Customer-specific deployments ensure consistent performance and data isolation.

Analytics

Service usage metrics
Yes
Metrics types
User volume
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Data can be extract on demand from some applications (via CSV download), and in other cases we will work with the customer to provide secure extracts of data as required.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
SLAs vary depending on the level of incident response required by the customer (details provided in pricing document), with accompanying SLA breach/remedy definitions.
Approach to resilience
Cogna’s platform is built to ensure business continuity and predictable performance.
Resilient infrastructure: Services run on high-availability cloud infrastructure with multi-zone redundancy.
Continuity planning: Business Continuity and Disaster Recovery frameworks are tested annually.
Rapid recovery: Defined RTO/RPO objectives and encrypted daily backups protect against data loss or service interruption.
Change discipline: All production changes are reviewed, tested, and reversible, minimising operational risk.
Outage reporting
Public dashboard and email notification

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Cogna restricts access to management interfaces and support channels using strict role-based access controls (RBAC) enforced via Microsoft Entra ID (Azure Active Directory). Access is limited to authorized personnel based on job function and is reviewed regularly. Customer support channels are accessible only to designated support and engineering staff. Access to sensitive systems is logged and monitored for anomalies. Administrative tools and production systems are logically segregated, with network-level controls and VPN requirements in place to limit exposure. Access is promptly revoked upon role change or offboarding.
Access restriction testing frequency
At least once a year
Management access authentication
Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Cogna maintains a comprehensive ISO27001-certified Information Security Program. Policies include: Acceptable Use, Asset Management, SDLC, Incident Response, Access Control, Data Classification, Vendor Management, and Business Continuity. These are reviewed and approved annually.

The Digital Security Officer (DSO) owns and maintains the Information Security Management System (ISMS), reports on performance to senior leadership, and ensures conformity with ISO standards . All staff must acknowledge the policies upon onboarding and annually thereafter. Security training is mandatory and tracked via a Compliance Automation Platform, with additional awareness campaigns for role-specific risks .

Compliance is enforced through access controls, quarterly audits, vulnerability management, and incident response protocols. Exceptions to policies require executive approval and are reviewed annually
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Automation and disciplined engineering sustain quality and agility.
Controlled change: Every code change undergoes automated testing, peer review, and deployment to a dedicated staging environment before being released to production.
Environment separation: Customers only access the production environment, ensuring that pre-release testing and verification occur in isolated environments under Cogna’s control.
Lifecycle management: Assets and dependencies follow documented maintenance and retirement processes.
All production changes are reviewed, tested, and reversible, minimising operational risk.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Cogna uses continuous and proactive methods to scan and manage vulnerabilities. Threats are assessed via DevSecOps security platform with SCA and SAST capabilities, Microsoft Defender for Cloud, and external penetration testing. Patching timelines are tied to SLAs tracked in our DevSecOps platform, which also auto-generates remediation tickets. Threat intelligence is sourced from the DevSecOps platform’s constantly updated feed, Microsoft’s Defender suite, subscriptions to the Internet Storm Center (ISC), and partner notifications, ensuring timely responses to emerging threats.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Continuous security monitoring and automated alerting safeguard against unauthorised activity. We use an application security platform, to continuously perform Static Code Analysis (SAST), Dynamic Application Security Testing (DAST), Open Source Analysis (SCA), Secrets Leakage Detection, and Cloud Security Posture Management.
Incident management type
Supplier-defined controls
Incident management approach
Cogna has pre-defined incident response processes for common events as part of its ISO27001:2022-certified Information Security Program. Incidents can be reported via internal channels like Slack or email. Customers are notified via email and Cogna’s public status page. Post-incident reports are shared with affected customers detailing root cause and actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Free trial depends on customer requirements. More details on request.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Prescient Security
ISO/IEC 27001 accreditation date
Thursday 10 July 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F6fa72be-f889-4b1a-9d47-a7c4f91e2043
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
SOC2 Type 2 accreditation

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at finance@cogna.co. Tell them what format you need. It will help if you say what assistive technology you use.