Cognite Flows Partner Policies
PART 1 - COGNITE FLOWS SHARED RESPONSIBILITY MODEL
This Shared Security and Operational Responsibility Model establishes the allocation of security and operational responsibilities between Cognite and the Partner in connection with the development, certification, and deployment of Partner Applications on CDF using Cognite Flows.
This model is based on established shared responsibility frameworks used in leading cloud platform environments, adapted specifically for the Cognite Flows Partner Program. It is the Parties' shared objective to ensure that End Customers of Partner Applications receive a secure, reliable, and compliant experience.
This document consists of:
(a) Joint responsibility Matrix
(b) Security Incident Procedures
(c) Minimum Security Standards
The Matrix is divided into three domains:
• Cognite's Responsibility — areas for which Cognite is solely responsible;
• Shared Responsibility — areas for which both Parties bear responsibility, with the specific allocation as described; and
• Partner's Responsibility — areas for which the Partner is solely responsible.
Review of the Joint Responsibility Matrix
The Parties shall review this Joint Responsibility Matrix at least annually and shall update it as reasonably required to reflect changes in the Partner Application, Cognite Flows, CDF, or applicable legal and regulatory requirements. Any amendments to this Part 1 shall be agreed in writing by both Parties.
Responsibility Allocation by Domain
Infrastructure and Platform Security
| Responsibility Area | Cognite | Partner |
|---|---|---|
| Physical security of data centres and cloud infrastructure | Sole | None |
| Security of the CDF platform layer (compute, storage, networking) | Sole | None |
| Security of Cognite Flows core components | Sole | None |
| CDF API security, rate limiting, and access control framework | Sole | None |
| Availability and uptime of CDF in accordance with the Cognite SLA | Sole | None |
| Patching and updating of CDF and Cognite Flows Toolkit components | Sole | None |
| Monitoring and alerting on CDF platform security events | Sole | None |
| Penetration testing of the CDF platform | Sole | None |
Identity and Access Management
| Responsibility Area | Cognite | Partner |
|---|---|---|
| Provision and management of CDF API authentication framework | Sole | None |
| Implementation of authentication within the Partner Application | Guidance, tooling and testing during approvals | Sole |
| Management of Partner's own developer and admin credentials | None | Sole |
| Ensuring principle of least privilege in Partner Application design | Application Review | Sole |
| Ensuring principle of least “necessary capabilities” in Partner application design | Application review | Sole |
Data Security, Application Security, and Secure Software Development
| Responsibility Area | Cognite | Partner |
|---|---|---|
| Encryption of data at rest within CDF | Sole | None |
| Encryption of data in transit between CDF and the Partner Application | Sole for the CDF side; | Sole for the Partner Application side |
| Secure application implementation | Partner Application review | Sole |
| Supply chain security (third-party libraries and components used in the Partner Application) | None | Sole |
| Security of Cognite Flows APIs and core libraries | Sole | Inform Cognite if become aware of issues |
| Guardrailing and security of AI coding tool | Sole for CDF | Sole for Partner Application development |
| Secure development practices and code quality for the Partner Application | Certification standards and review | Sole |
| Static code analysis and dependency scanning | Certification review | Sole |
| Vulnerability management and patching of the Partner Application post-certification | None | Sole |
| Incident detection and response for security events originating in the Partner Application | Shared | Shared |
| Incident detection and response for security events originating in CDF | Sole | Inform and cooperate |
| Classification and labelling of End User data ingested by the Partner Application | None | Sole |
| Notification to the other Party of relevant security events | Shared — each Party notifies the other promptly upon discovery | Shared |
Compliance and Audit
| Responsibility Area | Cognite | Partner |
|---|---|---|
| Maintenance of Cognite's own compliance/regulatory certifications (e.g. ISO 27001, SOC 2) | Sole | None |
| Making Cognite compliance documentation available to Partner as reasonably required | Sole | None |
| Compliance of the Partner Application with applicable laws and regulations | None | Sole |
| Maintenance of the Partner's own applicable regulatory certifications | None | Sole |
| Supply chain security (third-party libraries and components used in the Partner Application) | None | Sole |
Security Incident Procedures minimum requirements
(a) Each Party shall maintain and operate a documented security incident response procedure.
(b) In the event of a security incident related to the Application, the parties will notify customers, End Customers, each other, and other interesting parties as specified in the Program policies.
(c) In the event of a security incident related to the Application, the parties will cooperate to resolve the incident, according to requirements in the Program policies.
Minimum Security Standards
The Partner shall at all times, in respect of Partner Applications, maintain as a minimum the following security standards, as detailed in the Security Baseline of the Program Policy:
(a) encryption of all data at rest using AES-256 or equivalent;
(b) encryption of all data in transit using TLS 1.2 or above;
(c) multi-factor authentication for all administrative access to Partner Application development environments;
(d) vulnerability scanning of Partner Application code and dependencies on each release;
(e) a documented and tested incident response plan;
(f) annual penetration testing of production Partner Application development environments by a qualified third party and specified in current Program Policy; and
(g) compliance with Cognite's published Cognite Flows security baseline as updated from time to time in Program Policies.
PART 2 - PROGRAM POLICIES
This document specifies the Program policies as Cognite may update from time to time.
APPLICATION APPROVAL PROCESS
Overview
All Partner Applications must undergo and receive approval from Cognite before they may be deployed to, or commercialised with, End Customers. The approval process is designed to ensure that Partner Applications meet Cognite's security, quality, and compatibility standards.
Submission Requirements
The Partner shall submit the following to Cognite's designated partner certification team:
(a) a completed application submission form (template available on Cognite's partner portal);
(b) full technical documentation, including architecture diagrams, data flow diagrams, and API usage documentation;
(c) a completed security self-assessment questionnaire, addressing the Partner's obligations under the Joint Responsibility Matrix in Part 1;
(d) results of the Partner's own security testing, including penetration testing results where applicable;
(e) access credentials and a live or sandbox environment for Cognite's testing team; and
(f) a description of the Partner’s preferred Support Model for the Partner Application.
Review Timeline
Cognite shall use commercially reasonable endeavours to complete its initial review within thirty (30) business days of receiving a complete submission. Cognite shall notify the Partner of: (a) certification approval; (b) conditional approval with required remediation items; or (c) rejection with reasons.
Remediation
Where Cognite issues a conditional approval, the Partner shall complete all required remediation items and resubmit within forty-five (45) business days. Cognite shall complete its review of the resubmission within fifteen (15) business days.
Certification Validity
Application Certification is valid for the specific version of the Partner Application submitted. A new or update to a certified Partner Application requires re-submission for certification. Cognite may, at its discretion, conduct periodic re-assessments of certified Partner Applications to verify ongoing compliance.
Vulnerability remediation
The Partner is responsible for patching vulnerabilities in applications within the following timelines:
● Critical: 15 days
● High: 30 days
● Medium: 90 days
Cognite has the right to disable vulnerable applications unless they are patched within these timeframes. Cognite has the right to immediately disable or restrict applications where there is reason to expect that the application is actively abused or forms an immediate risk to the customer’s data
Certification Criteria
Cognite's certification assessment may include, without limitation, the following criteria:
| Category | Assessment Areas |
|---|---|
| Security | Adherence to Joint Responsibility Matrix; data encryption standards; access control and authentication; vulnerability management; incident response readiness |
| Data Protection | Compliance with applicable data protection laws; data minimisation; End User consent mechanisms; data retention and deletion procedures |
| Quality | Code quality and stability; error handling; performance benchmarks; |
| Compatibility | Compatibility with current and near-future versions of CDF and Cognite Flows |
| Acceptable use | The application adheres to documented API limitations and does not abuse CDF APIs or resources |
| Compliance | Adherence to Program Policies; export control compliance; anti-bribery compliance |
| Documentation | Adequacy of user documentation; support procedures; release notes |
Security Incident Procedures minimum requirements
Each Party shall maintain and operate a documented security incident response procedure.In the event of a security incident that affects or may affect the other Party or End Customers, the discovering Party shall:
(a) notify the other Party promptly in writing, and in any event within 24 hours;
(b) provide a description of the incident, the data and systems affected, and the steps taken or planned to contain and remediate it; and
(c) cooperate fully with the other Party in investigating and remediating the incident.
(d) Cognite shall have discretion in relation to notifying a Cognite End Customer of a security incident and Partner shall not notify Cognite End Customers without Cognite’s written consent.
Builder Certification Program
Certification Requirement.
All Partner personnel who develop, modify, or maintain Partner Applications using Cognite Flows ("Certified Developers") must hold a valid Cognite Flows Custom Apps Builder Certificate issued by Cognite.
Certification Process
Builder Certification is obtained through the certification pathway set out by Cognite, which requires, at a minimum:
(a) completion of the Cognite Flows Foundations Academy course via the Cognite Hub learning platform;
(b) attendance at and participation in a Cognite-facilitated hands-on enablement session, conducted against live CDF data; and
(c) sign-off by the Cognite session facilitator on completion of the learning path.
Cognite shall maintain a reasonable capacity to schedule enablement sessions for Partner personnel and shall confirm certification status to the Partner in writing.
Certification Validity and Renewal
A Builder Certificate is valid for six (6) months from the date of grant. The Partner is responsible for ensuring that Certified Developers renew their certification before expiry. Renewal requires the Certified Developer to complete the current version of the Cognite Academy course.
Minimum Certified Developer Requirement
The Partner shall maintain at least one (1) active Certified Developer within its organisation at all times during the Subscription Period. This minimum is required to ensure the Partner is capable of providing continuous support and maintenance for any deployed Partner Applications. If the Partner's last remaining Certified Developer's certificate lapses or the individual leaves the Partner's organisation, the Partner shall take immediate steps to obtain certification for at least one replacement individual.
Where the Partner is unable to maintain the minimum number of Certified Developers, Cognite may, at its discretion, suspend the Partner's ability to deploy new Partner Applications until the requirement is met.
Relationship to Application Certification
Builder certification authorizes an individual to build Partner Applications in End Customer environments. It does not, in itself, authorize deployment of a Partner Application to an End Customer’s production environment. Each Partner Application must separately obtain Cognite’s approval before production deployment.