SOC 2 Type II

SECURITY

SECURITY AND TRUST AT CIMENTO AI

Cimento helps security teams reduce human risk through AI-powered phishing simulations and adaptive, personalized training. Because Cimento’s platform connects to your HRIS, SIEM, and other systems that touch employee data, protecting that data is core to how the company designs and operates its product.

  • SOC 2 Type II compliant

  • Hosted on Amazon Web Services (AWS)

  • Managed database infrastructure with automated, encrypted backups

  • Continuous automated code and infrastructure security scanning

  • Annual third-party penetration testing

  • Formal Information Security Management System (ISMS)

  • Least-privilege access to integrated HR and security data

COMPLIANCE

  • Cimento is SOC 2 Type II compliant, reflecting the operating effectiveness of its security controls over an extended period of monitoring.

  • A cross-functional ISMS Committee owns security policy, risk management, and audit preparation.

DATA CENTER AND NETWORK SECURITY

  • Cimento is hosted on Amazon Web Services (AWS), using managed, highly available database infrastructure.

  • AWS maintains compliance with a broad set of industry programs, including ISO 27001, SOC 1/2/3, and PCI DSS Level 1.

APPLICATION SECURITY

  • Source code undergoes continuous static analysis to identify vulnerabilities before reaching production.

  • Container images are scanned for known vulnerabilities prior to deployment.

  • Ongoing automated vulnerability scanning is performed across the environment.

  • Annual penetration tests are conducted by an independent third party.

DATA SECURITY

  • Customer and employee data handled by Cimento — including HRIS integration data, simulation results, and training records — is managed under least-privilege access principles.

  • Database backups are automated and encrypted, with a rolling retention window to support recovery.

  • Access to production infrastructure is restricted to authorized personnel.

SECURITY POLICIES & GOVERNANCE

  • Cimento maintains a documented Information Security Management System (ISMS), with policies reviewed and approved by company leadership.

  • Security responsibilities are formally assigned through the company’s ISMS Committee.

SOFTWARE DEVELOPMENT LIFE CYCLE (SDLC)

  • Code changes follow a defined development process that includes automated security scanning prior to release.

  • Security reviews are integrated into the company’s engineering workflow as part of its ongoing SOC 2 Type II compliance.

RESPONSIBLE AI & DATA PROTECTION

  • Cimento’s platform uses AI to power adaptive phishing simulations, employee risk scoring, and on-demand personalized training content.

  • Because its AI features operate on sensitive employee behavioral and HR-integrated data, data protection is treated as a core design requirement rather than an afterthought.

  • The company continues to formalize responsible-AI governance as part of its broader security and compliance program.

RESPONSIBLE DISCLOSURE

Anyone who discovers a potential security vulnerability or has questions about Cimento’s security practices can reach the security team at support@cimento.ai, and will receive a response as soon as possible.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.

Get Started

See It Live

Explore how modern phishing simulations and real-time human risk insights can strengthen your security posture. Let’s talk.