Cogna Platform
Cogna Platform for hosting and deploying AI-enabled software
Features
- AI-assisted application configuration in weeks, not months
- Integrates with existing systems: SAP, databases, APIs
- Interactive dashboards with real-time data visualisation
- Geospatial mapping and location-based operational features
- Role-based permissions control access
- AI Synthesis supports app development and deployment
- Application Unit pricing structure
Benefits
- Deploy operational solutions in weeks instead of years
- Applications evolve continuously with your changing needs
- Connects easily with your existing enterprise systems and databases
- Modern cloud architecture scales to meet demand efficiently
- Expert guidance throughout discovery, design, and deployment phases
- Solutions Strategist available to support development and deployment
- Cogna's Discover, Define, Deliver process enables rapid development
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 0 5 9 9 2 3 2 9 2 1 0 9 1 5
Contact
COGNA LTD
Craig Moore
Telephone: 07920523668
Email: finance@cogna.co
About your service
- Service categories
-
Application Development and Deployment
AI platforms
- Search and knowledge discovery
AI life cycle
- AI Build Software
AI software services
- Generative AI Software Services
- Document AI Software Services
- Personalize AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Web-based applications requiring internet connectivity
- Browser compatibility required (modern web browsers)
User support
- Email or online ticketing support
- Yes
- Support response times
- Varying response time depending on severity
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Testing performed by web chat supplier (Intercom)
- Onsite support
- Yes
- Support levels
-
Cogna provides a multi-layered support model with Solutions Strategists at the center, supported by technical support teams:
- In-application support interface (Intercom integration)
- Email support and ticketing system
- Telephone support during Normal Working Hours
- Dedicated Solutions Strategist relationship for each customer
- Application hosting and infrastructure management
- Defect resolution with severity-based prioritization
- Platform maintenance and security updates
- Reasonable change requests to extend functionality
- Continuous iteration to ensure applications remain useful
Full details on SLA tiers and pricing are listed in the price document. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Onsite & online training is provided, along with documentation as needed
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data can be extract on demand from some applications (via CSV download), and in other cases we will work with the customer to provide secure extracts of data as required.
- End-of-contract process
- Data extract is included
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is provided in plain text format and written in simple to understand text
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- App rendering will vary and not all features will be available
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- Data ingest / egress
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- App functionality & interface within the platform
Scaling
- Independence of resources
-
The platform scales vertically and elastically to maintain reliability as workloads grow.
Adaptive capacity: Compute and storage resources scale automatically based on demand and monitored utilisation.
Performance assurance: Continuous monitoring and periodic stress testing sustain fast response times under load.
Dedicated tenancy: Customer-specific deployments ensure consistent performance and data isolation.
Analytics
- Service usage metrics
- Yes
- Metrics types
- User volume
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Data can be extract on demand from some applications (via CSV download), and in other cases we will work with the customer to provide secure extracts of data as required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- SLAs vary depending on the level of incident response required by the customer (details provided in pricing document), with accompanying SLA breach/remedy definitions.
- Approach to resilience
-
Cogna’s platform is built to ensure business continuity and predictable performance.
Resilient infrastructure: Services run on high-availability cloud infrastructure with multi-zone redundancy.
Continuity planning: Business Continuity and Disaster Recovery frameworks are tested annually.
Rapid recovery: Defined RTO/RPO objectives and encrypted daily backups protect against data loss or service interruption.
Change discipline: All production changes are reviewed, tested, and reversible, minimising operational risk. - Outage reporting
- Public dashboard and email notification
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Cogna restricts access to management interfaces and support channels using strict role-based access controls (RBAC) enforced via Microsoft Entra ID (Azure Active Directory). Access is limited to authorized personnel based on job function and is reviewed regularly. Customer support channels are accessible only to designated support and engineering staff. Access to sensitive systems is logged and monitored for anomalies. Administrative tools and production systems are logically segregated, with network-level controls and VPN requirements in place to limit exposure. Access is promptly revoked upon role change or offboarding.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Cogna maintains a comprehensive ISO27001-certified Information Security Program. Policies include: Acceptable Use, Asset Management, SDLC, Incident Response, Access Control, Data Classification, Vendor Management, and Business Continuity. These are reviewed and approved annually.
The Digital Security Officer (DSO) owns and maintains the Information Security Management System (ISMS), reports on performance to senior leadership, and ensures conformity with ISO standards . All staff must acknowledge the policies upon onboarding and annually thereafter. Security training is mandatory and tracked via a Compliance Automation Platform, with additional awareness campaigns for role-specific risks .
Compliance is enforced through access controls, quarterly audits, vulnerability management, and incident response protocols. Exceptions to policies require executive approval and are reviewed annually - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Automation and disciplined engineering sustain quality and agility.
Controlled change: Every code change undergoes automated testing, peer review, and deployment to a dedicated staging environment before being released to production.
Environment separation: Customers only access the production environment, ensuring that pre-release testing and verification occur in isolated environments under Cogna’s control.
Lifecycle management: Assets and dependencies follow documented maintenance and retirement processes.
All production changes are reviewed, tested, and reversible, minimising operational risk. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Cogna uses continuous and proactive methods to scan and manage vulnerabilities. Threats are assessed via DevSecOps security platform with SCA and SAST capabilities, Microsoft Defender for Cloud, and external penetration testing. Patching timelines are tied to SLAs tracked in our DevSecOps platform, which also auto-generates remediation tickets. Threat intelligence is sourced from the DevSecOps platform’s constantly updated feed, Microsoft’s Defender suite, subscriptions to the Internet Storm Center (ISC), and partner notifications, ensuring timely responses to emerging threats.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Continuous security monitoring and automated alerting safeguard against unauthorised activity. We use an application security platform, to continuously perform Static Code Analysis (SAST), Dynamic Application Security Testing (DAST), Open Source Analysis (SCA), Secrets Leakage Detection, and Cloud Security Posture Management.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Cogna has pre-defined incident response processes for common events as part of its ISO27001:2022-certified Information Security Program. Incidents can be reported via internal channels like Slack or email. Customers are notified via email and Cogna’s public status page. Post-incident reports are shared with affected customers detailing root cause and actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Free trial depends on customer requirements. More details on request.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Prescient Security
- ISO/IEC 27001 accreditation date
- Thursday 10 July 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- F6fa72be-f889-4b1a-9d47-a7c4f91e2043
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
- SOC2 Type 2 accreditation
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-