Cognatum

Industries / Other regulated enterprises

One knowledge layer every team uses.

Your business units keep buying their own AI tools. This gives them one approved place to read from making them more effective and more compliant.

Without Cognatum

A third team bought one.

“I need an AI architecture I can defend to security, compliance, and the CIO.”

Director of Enterprise Apps and Data

Every business unit is solving the same problem separately, and security is reviewing each answer after it has already been given.

One business unit buys an AI tool. Then a second. Then a third, and each points at a different pile of files.

Permissions are set differently in every repository. None of them is the authoritative one, so the same question has three answers and nobody signed any of them.

Then one of the source documents changes, and none of the three tools knows which of their answers depended on it. Then a security review blocks an integration you own, and you are asked to defend an architecture that nobody designed.

Which of our repositories is the authoritative one? Ask
Ungoverned answer NO RECORD

The document store. The wiki mirrors it and the procedure repository is a subset.

No source · no approver · no date

Where did this come from? Nothing on this answer can say.

Why this industry

We have run knowledge bases.

The people behind Cognatum have run knowledge bases as a business for years, not as a side effect of building something else.

RocketDocs has served regulated response teams from a knowledge base since long before generative AI made this question urgent.

That history is why the product starts from the record rather than from retrieval.

These are the failure modes we watched happen, over and over:

  • The answer existed and nobody could find it.
  • Three versions existed and nobody knew which one was current.
  • The person who knew left, and the knowledge left with them.
  • Someone answered from memory and was confidently wrong.

What we will not claim

Cognatum does not make you compliant with anything. No software does.

What it produces is evidence you can put in front of a reviewer: which entry answered, who approved it, when, and from what source. Your obligations stay yours, and your auditors still audit you.

Which retention period applies to client trade communications?

Entry SOP-4471

  1. v4 In force

    Retention extended to seven years for client trade communications.

    D. Whitfield, Records management · 2026-07-02

  2. v3 Superseded · retained

    Chat channels brought into scope.

    D. Whitfield, Records management · 2025-11-14

  3. v2 Superseded · retained

    Exception process added for legal hold.

    M. Alvarez, Compliance · 2025-03-09

  4. v1 Superseded · retained

    First approved version.

    M. Alvarez, Compliance · 2024-06-18

→ what the entry said on a date is a lookup

With Cognatum

What it does in your company.

Work already produces knowledge. It lands in documents, threads, tickets, and records, spread across whichever systems each team happens to use.

Capture

Work becomes entries

Each document, thread, or ticket becomes an entry with a title, a body, a link to where it came from, and an owner.

Approve

One gate, one name

A named person approves the entry. Nothing is served until somebody does. That gate is what separates a knowledge base from a folder.

Clearance

Answers stop at the boundary

What comes back is decided by the asker, at the point the answer is made. An agent answers within the clearance of the person it acts for.

Gaps

Unanswered becomes a work list

A question with no approved answer is recorded as a gap with an owner, instead of being absorbed and forgotten.

Frameworks

What each framework asks.

Instrument What it asks of you What we supply toward it
ISO 27001 That information security is managed by a system with defined controls, documented ownership, and evidence that the controls operate. Every entry has a named owner and an approval record. Access to an entry is decided by clearance rather than by who found the file.
SOC 2 That you can show an auditor how a control worked over a period, not only that it exists today. The approval trail is kept per entry and per version, so a period can be evidenced from the record rather than reconstructed from memory.
GDPR That personal data has a lawful basis, a defined retention period, and a record of processing. Entries carry their source, so where an answer came from is a matter of record. Retention and lawful basis remain yours to set.

This table describes obligations that fall on your organization, and the evidence Cognatum produces toward them. It is not a claim of certification or conformity, ours or yours.

In practice

Three repositories, one assistant.

A team asks to point an AI assistant at a document store, a wiki, and a validated procedure repository, each with its own permissions.

You map the repositories, the identities, and the sensitivity labels once. Nothing is served until a named person has approved it.

Clearance is decided when the answer is made, so nobody gets an answer they could not have opened themselves. Denials are recorded.

Change a source and every entry built on it is flagged for re-check. The record shows the source, the approver, and the version behind each answer.

Requests in

One assistant, one asker

  • Approved disclosure language
  • Current supervisory procedure
  • A draft nobody has signed
  • An entry retired last quarter

Served

With approver, date, version

  • Disclosure D-214 rev 6

    J. Mercer · approved 2026-07-14

  • Procedure WSP-11 v4

    Supervision · approved 2026-06-30

Not served

Not fetchable at all

  • Draft entry

    No approval on record

  • Retired entry

    Archived 2026-04-11

Common questions

What architects ask first.

Do we have to move our content into this?

No. Entries are drawn from the systems where work already happens, and each entry links back to the file it came from. Your repositories stay where they are.

How do permissions work across systems that disagree?

Clearance is decided at the point the answer is made, not only at the document store. Two people can ask the same question and get different answers, or none. Denials are recorded.

What connects to it?

Assistants and agents connect over MCP, the open standard AI assistants use to reach outside data. Applications and workflows connect over a plain API. Both directions are supported.

What happens when two approved sources disagree?

They are held apart and routed to a person to settle. They are never averaged into one confident answer. A conflict is a decision, so a person makes it.

Is this a migration project?

No. The loop drafts entries from work your teams are already doing, and your people approve a few at a time. There is no six-month cleanup before anything is usable.

Knowledge governed. Intelligence everywhere.

See it on your own content, in your own environment.