# Security at NiCE | Cognigy

NiCE | Cognigy provides enterprise-grade AI automation and conversational platforms that enable organizations to deliver secure, compliant, and human-centric customer experiences. Headquartered in Düsseldorf, Germany, the company operates under a unified governance framework certified to international standards including ISO 27001, ISO 27701, ISO 42001, SOC 2 Type II, TISAX and BSI C5. NiCE | Cognigy’s platform combines advanced automation, AI orchestration, and natural language understanding (NLU) with a strong focus on data protection, reliability, and regulatory compliance.

## Compliance

ISO 27001

ISO 27701

ISO/IEC 42001:2023

TISAX

SOC 2 Type II

BSI C5 Type II

PCI DSS - SAQ D, Merchant

HIPAA

GDPR

CCPACOMPLIANT

CCPA

AIC4

CSA STAR CAIQ

EcoVadis

VPAT

## Controls

Updated less than a minute ago

[**Infrastructure security**](https://trust.cognigy.com/controls#infrastructure-security)

- Unique account authentication enforced
- Unique network system authentication enforced
- Remote access MFA enforced

[**Organizational security**](https://trust.cognigy.com/controls#organizational-security)

- Asset disposal procedures utilized
- Production inventory maintained
- Portable media encrypted

[**Product security**](https://trust.cognigy.com/controls#product-security)

- Data encryption utilized
- Control self-assessments conducted
- Data transmission encrypted

[**Internal security procedures**](https://trust.cognigy.com/controls#internal-security-procedures)

- Cybersecurity insurance maintained
- Configuration management system established
- SOC 2 - System Description

[**Data and privacy**](https://trust.cognigy.com/controls#data-and-privacy)

- Customer data deleted upon leaving

[**Responsible AI**](https://trust.cognigy.com/controls#responsible-ai)

- AI system impact assessment
- Determining the scope of the AI management system
- AI objectives and planning

## Data collected

- Customer personally identifiable information
- Employee personally identifiable information
- Credit card information
- Personal health information

## Updates

### 2026 Compliance Update

Published November 10, 2025

We are enhancing our Trust Center in 2026 to include additional control mappings, including alignment of our SOC 2 control framework with the HITRUST CSF and expanded mappings to HIPAA requirements, further strengthening transparency for customers in regulated industries.
