Handbook / Catalogues / CISO & vendor briefing

For CISOs, DPOs, vendor risk, procurement

The document we hand to the security and procurement teams who actually have to sign.

Data handling. GDPR posture. Intellectual property. AI Act / ISO 42001 / NIST AI RMF alignment. Vendor risk. Insurance certificates. Named references. Read in 15 minutes by a senior security buyer who doesn't have time for marketing copy.

01 · Company essentials

Legal entityCohorte SAS
Country of registrationFrance
Registered officeParis, France
Secondary officeRabat, Morocco
Year founded2024
Headcount~6 (founder, coordinator, partnerships lead, mentor network)
Tax residencyFrance
Insurance statusActive. Certificates available within 24h of NDA signature.
Audited financialsAvailable under NDA

02 · Data handling posture

What we do, do not do, and refuse to do with client data.

Data extractionCohorte never extracts, copies, or transfers client production data to its own infrastructure. Period.
Data retentionCohorte does not retain client production data. Any data shared during scoping is held only for the duration of the engagement and deleted at close.
Training on client dataCohorte does not train, fine-tune, or otherwise use client data to improve any model, product, or course. Contractual term in every MSA.
Training environmentTraining exercises use the client's own infrastructure, sample data we cannot retain, or public datasets. Default is the client's infrastructure.
Cross-client repurposingNo work product is repurposed across clients. Engagement IP is firewalled.
On-premise / on-site deliverySupported. AI Readiness assessment and 2 of 4 Team Bootcamp sessions can be delivered inside your firewall.
AI tools used in deliveryEnterprise-tier AI tools (Anthropic, OpenAI, Google, Microsoft) under no-retain configuration. Stack documented per engagement.
SubprocessorsDocumented per engagement. Standard MSA includes the list and right to object.

03 · GDPR & data residency

Controller / ProcessorLicense: Processor for learner identification data. Training engagements: generally Joint Controller for operational data and Processor for sample data the customer shares.
Data residency · LicenseEU (Frankfurt) by default. UK or Switzerland on request.
Data residency · BootcampEU (Paris / Frankfurt). Video transcoding routed via Mux, EU region.
Standard Contractual ClausesModule 2 and Module 3 available where applicable.
DPACohorte standard DPA available on request. We sign customer's DPA where reasonable.
Data subject rightsWithin 30 days. Process documented in DPA.
Cross-border transfersMinimised. Where present, SCCs in place; transfer logic documented per engagement.
Breach notificationWithin 24 hours of confirmed breach.

04 · Intellectual property & work product

Who owns what, after the engagement closes.

Methodology (LUMEN, TrustGate)Cohorte retains rights. Methodology is also publicly available; customers may apply it indefinitely without Cohorte's involvement.
Open-source reference stackgithub.com/Cohorte-ai. Released under permissive licenses (MIT or Apache 2.0). Customers may fork, modify, deploy at will.
Curriculum contentCohorte retains copyright. Customers receive a license to use within their organisation for the duration of the License or program.
Engagement deliverablesCustomer owns the deliverables produced for their engagement.
Customer's internal IPCustomer's. Cohorte never claims ownership of customer's pre-existing or engagement-derived business IP.
Joint IPBy default, none is created. Where it would be, explicit agreement is signed before the work begins.
Right to referenceCohorte does not name a customer publicly without written consent.

05 · Regulatory alignment

The frameworks the curriculum maps to, by section number. Not just by name.

EU AI ActArticle 9 (risk management), 10 (data governance), 12 (logging), 13 (transparency), 14 (human oversight), 15 (accuracy / robustness / cybersecurity), 17 (quality management). Mapping included as appendix to every Team Bootcamp and AI Readiness proposal.
ISO/IEC 42001Clauses 4-10. Cohorte curriculum touches each. Independent ISO 42001 certification supported by the AI Readiness playbook.
NIST AI RMFGovern · Map · Measure · Manage. Function-by-function mapping in the AI Readiness playbook.
SR 11-7 (US Fed)Model risk management. Cohorte's verification curriculum is the technical layer underneath SR 11-7 §III independent-validation expectations.
PRA SS1/23 (UK)Principles 1-4. Mapped in the FS vertical proposal.
DORA (EU)ICT third-party risk management. DORA-aligned documentation provided where Cohorte is an ICT third party.
GDPR Article 22Cohorte teaches how to design AI systems that respect Article 22, including the human-in-the-loop discipline that exempts an AI-assisted decision from Article 22 obligations.

06 · Security posture

SSOOkta, Azure AD, Google Workspace SSO on Curriculum License platform.
MFARequired for all Cohorte staff on internal systems.
Encryption in transitTLS 1.2 minimum. TLS 1.3 default on all customer-facing platforms.
Encryption at restAES-256 on data stores used for Curriculum License platform.
Audit logsAccess, completion, exports on Curriculum License platform.
Penetration testingAnnual external pen test of customer-facing platforms (schedule starts Q4 2026). Reports available under NDA.
Vulnerability managementContinuous dependency monitoring. Patches: critical within 72h, high within 7 days, medium within 30 days.
Internal access controlsPrinciple of least privilege. Time-bounded, logged per engagement.
Background checksPerformed on all Cohorte staff and embedded mentors prior to first engagement.
CertificationsISO 27001 alignment in progress (target audit 2027). SOC 2 readiness on the same roadmap.

07 · Insurance & liability

CoverageLimitNotes
Professional Indemnity€2,000,000 aggregateActive. Certificate within 24h. Higher limits negotiable.
Public Liability€5,000,000 aggregateActive. Covers on-site delivery.
Cyber Liability€1,000,000 aggregateActive. Data-breach response and notification costs.
Errors & OmissionsIncluded under PI
Liability cap (default MSA)Annual fees in last 12 monthsStandard market term. Negotiable per engagement.
Indemnification (IP)Standard MSA termCohorte indemnifies against third-party IP claims based on Cohorte methodology or curriculum.

08 · References

The named people who will take a reference call. Each is reachable after the customer signs a mutual NDA. Reference calls scheduled within 5 business days. Cohorte does not redact behind "global top-50 European bank" copy.

PwC France & Maghreb

Patrick Monteiro, CIO

Sponsor of the PwC AI Factory (60+ AI systems, 4,000+ Copilot users, +80% adoption in 6 months). Reference call covers operating model, governance design, scale.

OPIT

Riccardo Ocleppo, CEO

Sponsor of the AI tutoring engagement (−60% professor support, +40% student progression). Reference call covers pedagogical impact, faculty adoption, institutional integration.

By sector

Additional, under NDA

Cohorte identifies a named reference per sector (FS, PS, HE) where the engagement context warrants it. List extended quarterly.

09 · Procurement checklist

What we send you, in what order, when you ask.

ArtifactLead timeNotes
Insurance certificates24 hours after NDADirect from broker on letterhead.
Audited financials5 business days under NDALatest fiscal year.
Cohorte standard MSAImmediateIndustry-standard. Customer redlines welcome.
Cohorte standard DPAImmediateGDPR-aligned. We sign customer's DPA where reasonable.
Vendor questionnaire5 business daysSIG-Lite / CAIQ supported.
InfoSec policy summary3 business daysPublic summary plus controls map.
References5 business daysNamed contact, scheduled call.
Subprocessor listImmediatePer-engagement, MSA exhibit.
BCDR plan5 business daysCustomer-facing summary; full plan under additional NDA.

Talk to Charafeddine directly. No sales gate.

Procurement on the discovery call from week one. Insurance certs in 24h. SIG-Lite / CAIQ returned in 5 business days. We make the security review the fast part of the engagement.

Email Charafeddine