Cogran Systems

SECURITY & COMPLIANCE

Security and compliance at Cogran

A clear view of how Cogran protects recreation, membership, registration, and payment information—and the documentation available for your security review.

Cogran is hosted on SOC 2-audited Microsoft Azure infrastructure and maintains application-level safeguards including encrypted connections, role-based access controls, secure authentication, and controlled administrative permissions. Payments are processed using Stripe’s PCI DSS Level 1–certified infrastructure.

Request security documentation →

How does Cogran protect customer data?

Cogran protects customer data through Azure hosting, per-client databases, encrypted communications, secure authentication, role-based access controls, and restricted administrative access.

Each client organization has its own database. Browser-to-server connections use HTTPS with a minimum documented TLS version of 1.2. Application, API, and database services are separated, and database access is restricted to the Cogran application/API layer and authorized administrators.

Client organizations retain ownership of their information. Cogran limits support access to circumstances such as resolving an issue, client instructions, or legal requirements.

Is Cogran SOC 2 compliant?

Cogran is hosted on SOC 2-audited Microsoft Azure infrastructure.

This statement describes the hosting infrastructure. It does not mean that Cogran holds its own SOC 2 report or that Azure’s audit independently assesses Cogran’s application-level controls. Cogran maintains its own safeguards for application access, authentication, permissions, and data handling.

Infrastructure reference: Microsoft Azure SOC 2 audit information.

How does Microsoft Azure support Cogran’s security?

Microsoft Azure provides Cogran’s managed cloud hosting and SQL database foundation. Azure infrastructure controls work alongside Cogran’s application and administrative safeguards.

Cogran’s documented controls include firewall and IP restrictions, Azure monitoring and alerts, Application Insights, and Azure Advisor. Production administration is restricted to authorized personnel, with strong passwords, two-factor controls, and authorized-device protections.

Is Cogran PCI DSS compliant?

Payments are processed using Stripe’s PCI DSS Level 1–certified infrastructure.

Cogran uses a Stripe-hosted payment model and maintains PCI-related self-assessment and attestation materials for procurement review. Stripe’s certification applies to Stripe’s infrastructure; it should not be described as an independent PCI DSS Level 1 certification of Cogran. An organization’s applicable PCI responsibilities depend on its payment setup and workflows.

Payment-provider reference: Stripe security and PCI compliance documentation.

Does Cogran store payment-card information?

Cogran does not store credit card numbers in its database. Card information is entered into Stripe’s hosted payment environment, where Stripe processes the cardholder data.

Each organization authorizes its own Stripe account. Cogran receives transaction results and identifiers needed for order status, reconciliation, and supported refunds. These transaction records are separate from credit card numbers.

Does Cogran support multifactor authentication and SSO?

Cogran can provide optional code-based dual authentication, adding a verification-code step to password sign-in. Production administrative access also uses documented two-factor controls.

For single sign-on (SSO), ask Cogran to confirm the supported configuration, identity-provider compatibility, scope, and any enterprise requirements for your organization. User authentication options should be confirmed during your security review before being included in a contract or RFP response.

How are administrative permissions controlled?

Cogran uses role-based access controls that can restrict menus, forms, functions, and data. Client administrators can create security groups aligned to staff responsibilities.

Unique user identities support accountability. Permissions follow a least-privilege approach and can be changed when responsibilities change or revoked when a user leaves. Production and support access is restricted to authorized personnel on a need-to-access basis, with logged or auditable access.

What security documentation is available for procurement teams?

Cogran can provide security and data-protection materials for procurement, IT due diligence, legal review, and security questionnaires.

Available materials include the security and data-protection overview; privacy and security policies; information-systems access controls; Stripe payment-security and PCI-related materials; the Incident Response Plan; Disaster Recovery Plan; Service Level Agreement; document-retention policy; and accessibility VPAT/roadmap materials.

Request the current documents relevant to your requirements. Policy summaries and accessibility materials describe their respective scope and should be reviewed alongside the current service terms and implementation.

How does Cogran respond to security incidents?

Cogran maintains a documented Incident Response Plan that assigns responsibilities and covers preparation, identification, containment, resolution, recovery, documentation, and follow-up.

The plan calls for impacted clients to be notified within 24 hours and for personnel to receive incident-response training. Procurement teams can request the current plan to review notification terms, responsibilities, and procedures.

The Disaster Recovery Plan describes layered backups, restoration of applications and databases, regional rebuilding where necessary, testing before service resumes, and client communication about expected recovery and restoration.

How can an organization request Cogran’s security documentation?

Email hello@cogransystems.com or contact your Cogran representative to request security documentation. Include your organization name, the materials you need, any security questionnaire, and your procurement timeline.

For an existing customer reporting a suspected security issue, contact Cogran support or your account representative promptly. Share a description and contact details; avoid including passwords, full card numbers, or sensitive participant records in an initial email.