Cognite Flows Partner Policies

PART 1 - COGNITE FLOWS SHARED RESPONSIBILITY MODEL

This Shared Security and Operational Responsibility Model establishes the allocation of security and operational responsibilities between Cognite and the Partner in connection with the development, certification, and deployment of Partner Applications on CDF using Cognite Flows.

This model is based on established shared responsibility frameworks used in leading cloud platform environments, adapted specifically for the Cognite Flows Partner Program. It is the Parties' shared objective to ensure that End Customers of Partner Applications receive a secure, reliable, and compliant experience.

This document consists of:

(a) Joint responsibility Matrix

(b) Security Incident Procedures

(c) Minimum Security Standards

The Matrix is divided into three domains:

• Cognite's Responsibility — areas for which Cognite is solely responsible;

• Shared Responsibility — areas for which both Parties bear responsibility, with the specific allocation as described; and

• Partner's Responsibility — areas for which the Partner is solely responsible.

Review of the Joint Responsibility Matrix

The Parties shall review this Joint Responsibility Matrix at least annually and shall update it as reasonably required to reflect changes in the Partner Application, Cognite Flows, CDF, or applicable legal and regulatory requirements. Any amendments to this Part 1 shall be agreed in writing by both Parties.

Responsibility Allocation by Domain

Infrastructure and Platform Security

Responsibility AreaCognitePartner
Physical security of data centres and cloud infrastructure

Sole

None

Security of the CDF platform layer (compute, storage, networking)

Sole

None

Security of Cognite Flows core components

Sole

None

CDF API security, rate limiting, and access control framework

Sole

None

Availability and uptime of CDF in accordance with the Cognite SLA

Sole

None

Patching and updating of CDF and Cognite Flows Toolkit components

Sole

None

Monitoring and alerting on CDF platform security events

Sole

None

Penetration testing of the CDF platform

Sole

None

Identity and Access Management

Responsibility AreaCognitePartner
Provision and management of CDF API authentication framework

Sole

None

Implementation of authentication within the Partner Application

Guidance, tooling and testing during approvals

Sole

Management of Partner's own developer and admin credentials

None

Sole

Ensuring principle of least privilege in Partner Application design

Application Review

Sole

Ensuring principle of least “necessary capabilities” in Partner application design

Application review

Sole

Data Security, Application Security, and Secure Software Development

Responsibility AreaCognitePartner
Encryption of data at rest within CDF

Sole

None

Encryption of data in transit between CDF and the Partner Application

Sole

for the CDF side;


Sole

for the Partner Application side


Secure application implementation

Partner Application review

Sole

Supply chain security (third-party libraries and components used in the Partner Application)

None

Sole

Security of Cognite Flows APIs and core libraries

Sole

Inform Cognite if become aware of issues

Guardrailing and security of AI coding tool

Sole for CDF

Sole for Partner Application development

Secure development practices and code quality for the Partner Application

Certification standards and review

Sole

Static code analysis and dependency scanning

Certification review

Sole

Vulnerability management and patching of the Partner Application post-certification

None

Sole

Incident detection and response for security events originating in the Partner Application

Shared

Shared

Incident detection and response for security events originating in CDF

Sole

Inform and cooperate

Classification and labelling of End User data ingested by the Partner Application

None

Sole

Notification to the other Party of relevant security events

Shared

— each Party notifies the other promptly upon discovery


Shared


Compliance and Audit

Responsibility AreaCognitePartner
Maintenance of Cognite's own compliance/regulatory certifications (e.g. ISO 27001, SOC 2)

Sole

None

Making Cognite compliance documentation available to Partner as reasonably required

Sole

None

Compliance of the Partner Application with applicable laws and regulations

None

Sole

Maintenance of the Partner's own applicable regulatory certifications

None

Sole

Supply chain security (third-party libraries and components used in the Partner Application)

None

Sole

Security Incident Procedures minimum requirements

(a) Each Party shall maintain and operate a documented security incident response procedure.

(b) In the event of a security incident related to the Application, the parties will notify customers, End Customers, each other, and other interesting parties as specified in the Program policies.

(c) In the event of a security incident related to the Application, the parties will cooperate to resolve the incident, according to requirements in the Program policies.

Minimum Security Standards

The Partner shall at all times, in respect of Partner Applications, maintain as a minimum the following security standards, as detailed in the Security Baseline of the Program Policy:

(a) encryption of all data at rest using AES-256 or equivalent;

(b) encryption of all data in transit using TLS 1.2 or above;

(c) multi-factor authentication for all administrative access to Partner Application development environments;

(d) vulnerability scanning of Partner Application code and dependencies on each release;

(e) a documented and tested incident response plan;

(f) annual penetration testing of production Partner Application development environments by a qualified third party and specified in current Program Policy; and

(g) compliance with Cognite's published Cognite Flows security baseline as updated from time to time in Program Policies.

PART 2 - PROGRAM POLICIES

This document specifies the Program policies as Cognite may update from time to time.

APPLICATION APPROVAL PROCESS

Overview

All Partner Applications must undergo and receive approval from Cognite before they may be deployed to, or commercialised with, End Customers. The approval process is designed to ensure that Partner Applications meet Cognite's security, quality, and compatibility standards.

Submission Requirements

The Partner shall submit the following to Cognite's designated partner certification team:

(a) a completed application submission form (template available on Cognite's partner portal);

(b) full technical documentation, including architecture diagrams, data flow diagrams, and API usage documentation;

(c) a completed security self-assessment questionnaire, addressing the Partner's obligations under the Joint Responsibility Matrix in Part 1;

(d) results of the Partner's own security testing, including penetration testing results where applicable;

(e) access credentials and a live or sandbox environment for Cognite's testing team; and

(f) a description of the Partner’s preferred Support Model for the Partner Application.

Review Timeline

Cognite shall use commercially reasonable endeavours to complete its initial review within thirty (30) business days of receiving a complete submission. Cognite shall notify the Partner of: (a) certification approval; (b) conditional approval with required remediation items; or (c) rejection with reasons.

Remediation

Where Cognite issues a conditional approval, the Partner shall complete all required remediation items and resubmit within forty-five (45) business days. Cognite shall complete its review of the resubmission within fifteen (15) business days.

Certification Validity

Application Certification is valid for the specific version of the Partner Application submitted. A new or update to a certified Partner Application requires re-submission for certification. Cognite may, at its discretion, conduct periodic re-assessments of certified Partner Applications to verify ongoing compliance.

Vulnerability remediation

The Partner is responsible for patching vulnerabilities in applications within the following timelines:

● Critical: 15 days

● High: 30 days

● Medium: 90 days

Cognite has the right to disable vulnerable applications unless they are patched within these timeframes. Cognite has the right to immediately disable or restrict applications where there is reason to expect that the application is actively abused or forms an immediate risk to the customer’s data

Certification Criteria

Cognite's certification assessment may include, without limitation, the following criteria:

CategoryAssessment Areas
Security

Adherence to Joint Responsibility Matrix; data encryption standards; access control and authentication; vulnerability management; incident response readiness

Data Protection

Compliance with applicable data protection laws; data minimisation; End User consent mechanisms; data retention and deletion procedures

Quality

Code quality and stability; error handling; performance benchmarks;

Compatibility

Compatibility with current and near-future versions of CDF and Cognite Flows

Acceptable use

The application adheres to documented API limitations and does not abuse CDF APIs or resources

Compliance

Adherence to Program Policies; export control compliance; anti-bribery compliance

Documentation

Adequacy of user documentation; support procedures; release notes

Security Incident Procedures minimum requirements

Each Party shall maintain and operate a documented security incident response procedure.In the event of a security incident that affects or may affect the other Party or End Customers, the discovering Party shall:

(a) notify the other Party promptly in writing, and in any event within 24 hours;

(b) provide a description of the incident, the data and systems affected, and the steps taken or planned to contain and remediate it; and

(c) cooperate fully with the other Party in investigating and remediating the incident.

(d) Cognite shall have discretion in relation to notifying a Cognite End Customer of a security incident and Partner shall not notify Cognite End Customers without Cognite’s written consent.

Builder Certification Program

Certification Requirement.

All Partner personnel who develop, modify, or maintain Partner Applications using Cognite Flows ("Certified Developers") must hold a valid Cognite Flows Custom Apps Builder Certificate issued by Cognite.

Certification Process

Builder Certification is obtained through the certification pathway set out by Cognite, which requires, at a minimum:

(a) completion of the Cognite Flows Foundations Academy course via the Cognite Hub learning platform;

(b) attendance at and participation in a Cognite-facilitated hands-on enablement session, conducted against live CDF data; and

(c) sign-off by the Cognite session facilitator on completion of the learning path.

Cognite shall maintain a reasonable capacity to schedule enablement sessions for Partner personnel and shall confirm certification status to the Partner in writing.

Certification Validity and Renewal

A Builder Certificate is valid for six (6) months from the date of grant. The Partner is responsible for ensuring that Certified Developers renew their certification before expiry. Renewal requires the Certified Developer to complete the current version of the Cognite Academy course.

Minimum Certified Developer Requirement

The Partner shall maintain at least one (1) active Certified Developer within its organisation at all times during the Subscription Period. This minimum is required to ensure the Partner is capable of providing continuous support and maintenance for any deployed Partner Applications. If the Partner's last remaining Certified Developer's certificate lapses or the individual leaves the Partner's organisation, the Partner shall take immediate steps to obtain certification for at least one replacement individual.

Where the Partner is unable to maintain the minimum number of Certified Developers, Cognite may, at its discretion, suspend the Partner's ability to deploy new Partner Applications until the requirement is met.

Relationship to Application Certification

Builder certification authorizes an individual to build Partner Applications in End Customer environments. It does not, in itself, authorize deployment of a Partner Application to an End Customer’s production environment. Each Partner Application must separately obtain Cognite’s approval before production deployment.