This overview lists application controls that can be verified in the current Cocopipe implementation. It does not claim SOC 2, ISO 27001, a specific encryption standard, or full statutory compliance without current published evidence.
Implemented application controls
- Administrative areas and actions use authentication and role-based permission checks.
- Protected state-changing admin requests use CSRF validation.
- Important administrative changes are written to audit logs where implemented.
- Supported uploads are checked by type, extension, size, and file signature.
Certification and infrastructure evidence
Contact Cocopipe for the current hosting, data-processing, and security evidence available for review. A provider certification is not represented as a Cocopipe certification.