top of page

Privacy Policy

1. Introduction 

1.1 COGSEC SOLUTIONS INC, operating as MindShield™ ("MindShield," "we," "us"), provides cognitive-security assessment and training services to organizations through the MindShield Cognitive Security Assessment (MCSA) (the "Platform").

 

1.2 This Privacy Notice ("Notice") describes how MindShield collects, uses, discloses, retains, and protects data processed through the Platform. It is addressed to the organizations that engage MindShield (each, a "Client") and to the individuals who complete assessments under a Client's programme (each, a "Participant").

 

1.3 MindShield provides its services exclusively through Client organizations. MindShield does not offer the Platform directly to individual consumers and has no direct commercial relationship with Participants.

 

1.4 This Notice sets out MindShield's standard practices. Where MindShield has agreed terms with a Client that differ from or are more restrictive than those set out here, those agreed terms govern in respect of that Client and its Participants and prevail over this Notice to the extent of any inconsistency.

 

1.5 This Notice should be read together with the applicable services agreement and, where executed, the data processing agreement between MindShield and the Client.


 

2. Definitions

For the purposes of this Notice:

 

"Aggregated Data" means De-Identified Data that has been combined across multiple records and reported only at segment level, subject to the K-Anonymity threshold set out in Section 8.4.

 

"Assessment Data" means Participant responses, actions, reaction times, and the cyber cognitive archetype scores and cognitive traits derived from them, together with any Attribute Data associated with a Pseudonymous ID.

 

"Attribute Data" means non-identifying organizational attributes, including department, tenure, location, and role level.

 

"Client Data" means Assessment Data and Attribute Data processed by MindShield on behalf of a Client. Client Data does not include De-Identified Data or Aggregated Data.

 

"De-Identified Data" means data derived from Assessment Data from which all Pseudonymous IDs, Client identifiers, and any Attribute Data capable of distinguishing an individual Participant or Client have been irreversibly removed, and which is not reasonably capable of being re-identified or linked to any Participant or Client, taking into account reasonably available means and applicable privacy and data protection laws.

 

"Direct Personal Information" means information that directly identifies an individual, including names, email addresses, employee identifiers, and government identifiers.

 

"Pseudonymous ID" means an opaque HMAC-SHA256 hash generated by the Client, on the Client's systems, which MindShield cannot reverse and for which MindShield holds no lookup table.

 

"Reports" means the structured insights and written outputs generated by the Platform and made available to the Client.

 

3. Roles of the Parties

3.1 In respect of Client Data, the Client is the accountable organization (controller) and MindShield acts as a service provider (processor). MindShield processes Client Data solely on the Client's documented instructions and for the purposes set out in Section 6, except where otherwise required by applicable law.

 

3.2 The Client determines the purpose and scope of its assessment programme, the deployment model applied under Section 4, the population invited to participate, and the use to which Reports are put within its organization.

 

3.3 In respect of De-Identified Data, MindShield acts as the accountable organization, on the basis set out in Section 8.

 

3.4 MindShield supports Clients in meeting their own privacy obligations, including by responding to requests made under Section 12 and by providing the information a Client requires to satisfy its transparency and notification duties.

 

 

4. Deployment Models

4.1 MindShield offers two deployment models, both of which do not permit MindShield to identify any individual participant. The model selected by the Client determines the categories of data MindShield receives.

 

4.2 Model A — Cohort (Anonymous). Assessment data is collected anonymously through a generic access link. No individual identifiers are generated, transmitted, or stored. 

 

4.3 Model B — Longitudinal (Pseudonymous). The Client converts Participant identities into non-reversible Pseudonymous IDs. Only the Pseudonymous ID and Assessment Data are transmitted to MindShield. 

 

5. Data Minimization and the Pseudonymous Architecture

5.1 Direct Personal Information is prohibited. MindShield's data classification standard designates Direct Personal Information as prohibited. It is rejected before entering the assessment pipeline and is never attached to an assessment record, transmitted to service providers, or stored on the Platform.

 

5.2 Effect. This architecture is designed so that the data MindShield holds is of materially reduced value in the event of unauthorized access, and so that MindShield's obligations to the Client can be discharged without MindShield ever processing Direct Personal Information.

 

6. Categories of Data and Purposes of Processing

6.1 MindShield processes Client Data for the following purposes only:

 

(a) delivering the contracted assessment and training programme;

(b) generating Reports for the Client;

(c) providing support, and maintaining the security, integrity, and availability of the Platform; and

(d) meeting MindShield's legal and regulatory obligations.


 

6.2 MindShield does not sell, rent, or trade Client Data or personal information, does not disclose it for the marketing purposes of any third party, and does not market to Participants.

 

6.3 MindShield processes uses De-Identified Data solely for:

 

  1. Validity, reliability, and fairness evaluation- producing the statistical evidence necessary to confirm that MindShield's assessments measure what they are designed to measure, perform consistently, and remain neutral and equitable across roles, functions, and populations;

  2. Service and model improvement- improving the accuracy and quality of MindShield's assessment and reporting capability, including the training and refinement of models used within the Platform; and

  3. Benchmarking- producing industry benchmark.

 

6.4 MindShield does not sell, rent, or trade Client Data or personal information, does not disclose it for the marketing purposes of any third party, and does not market to Participants.


 

6.5 Retention. De-Identified Data and Aggregated Data may be retained by MindShield indefinitely, as they no longer constitute personal information. Such data is not affected by the deletion of Client Data under Section 11 or by an erasure request under Section 12.

 

MindShield does not train or fine-tune models on Client Data. MindShield may use De-Identified and Aggregated Data to improve its assessment and reporting capability, as described in the Privacy Notice.


 

7. Use of Artificial Intelligence

7.1 Purpose. MindShield uses artificial intelligence to structure the quantitative and qualitative assessment outputs and generate Report content. MindShield's proprietary contribution resides in its assessment logic, design, architecture, scoring and report logic, and validation and control rules.

 

7.2 Foundation models. MindShield does not develop or host foundation models. Inference is performed through the enterprise application programming interfaces of established providers, currently Anthropic.

 

7.3 Data transmitted. Only Assessment Data is transmitted to inference providers. Direct Personal Information is never transmitted, as MindShield does not hold it. Under Model B, inference providers receive behavioural data associated with a Pseudonymous ID that neither they nor MindShield can reverse.

 

7.4 Terms of processing. Inference is performed on an in-flight basis to generate a response. MindShield's agreements with inference providers prohibit unauthorized retention, sharing, or use of transmitted data, and MindShield uses Zero-Data-Retention endpoints where applicable.

 

7.5 Validation. AI-generated output is not passed directly to a Report. Every generation is validated against MindShield's own controls before persistence or display, including required fields and value ranges, schema conformance, referential and session integrity, and expected rubric and skill coverage. Invalid or malformed generations are rejected.

 

7.6 Intended use and boundaries. The Platform is intended to support cognitive-security training, assessment, and report generation. It is not designed or supplied for autonomous high-stakes employment decisions, performance evaluations, unrestricted automated external actions, or clinical diagnosis. The Platform does not make, and is not capable of making, any automated decision concerning any Participant. All determinations arising from Reports are made by the Client through its own processes and governance.

 

7.7 Known limitations. AI outputs are probabilistic. MindShield's validation and control layer, and the Client's own governance, remain necessary components of the overall system.


 

8. Disclosure and Service Providers

9.1 Reports. Reports are made available to the Client and MindShield only. Where an intervention is indicated under Model B, MindShield provides the Client with the relevant Pseudonymous IDs, which the Client can re-map within its own systems. MindShield does not receive the result of that mapping.

 

9.2 Service providers. MindShield maintains an inventory of the enterprise providers used in the Platform and AI pipeline. Each provider's security and privacy posture is reviewed prior to adoption and monitored thereafter, and each is bound by data-processing terms prohibiting unauthorized retention, sharing, or use.

 

9.3 Legal process. MindShield may disclose data where required by applicable law, including in response to a valid court order, warrant, or subpoena, and will disclose only what is legally required. MindShield will notify the affected Client where permitted to do so.

 

9.4 Change of control. In the event of a merger, acquisition, or transfer of all or part of MindShield's business or assets, data may transfer to the successor entity, which shall remain bound by commitments no less protective than those set out in this Notice.

 

10. Data Location and Cross-Border Processing

10.1 Storage and at-rest processing. All Client Data is stored, and all at-rest processing is performed, within Canada, in the AWS Canada Region. MindShield does not store Client Data outside Canada. MindShield's infrastructure is hosted in data centres holding ISO 27001 and SOC 2 Type II certification. MindShield's own SOC 2 Type II certification is in progress.

 

10.2 Access. Authorized MindShield personnel may access data remotely for support, maintenance, and security purposes. Data remains hosted within Canada. Access is role-based, restricted to those with a demonstrable need, and logged.

 

10.3 Client-specific arrangements. Where a Client requires arrangements more restrictive than those set out in this Section, including full in-Canada processing, MindShield will address those requirements in the applicable services agreement, and those terms will prevail for that Client.

11. Retention and Disposal

11.1 MindShield retains data only for as long as necessary for the purpose for which it was collected. All client data will be terminated within 90 days of termination. 

 

11.2 Method of disposal. Cloud-hosted data is destroyed using secure deletion and cryptographic-erasure techniques consistent with the principles of NIST SP 800-88 (Guidelines for Media Sanitization). Deletion covers primary records and associated encrypted backups within the defined window.

 

11.3 Verification. Completion of scheduled and requested deletions is confirmed and recorded.

 

12. Erasure and Individual Requests

12.1 Erasure. A Client may request deletion of a specific Participant's data by providing the applicable Pseudonymous ID. MindShield purges all associated records without requiring, and without obtaining, knowledge of the individual's identity. Requests are actioned within the timeframe required by applicable law and the Client agreement.

 

12.2 Access and correction. As a service provider, MindShield supports the Client in responding to access and correction requests within the contracted scope. Under Model A, no individual record exists and individual-level requests cannot be actioned by either party; Clients selecting Model A should account for this in their own privacy notices to Participants.

 

12.3 De-Identified Data. For the avoidance of doubt, requests under this Section do not extend to De-Identified Data or Aggregated Data, which no longer identify any individual and from which no individual record can be located.

 

12.4 Routing. Participants should direct requests concerning their participation and results to their own organization, which is the accountable organization for the assessment programme. MindShield will assist the Client in responding.

 

14. Incident Response and Notification

14.1 MindShield maintains a Privacy Incident Response Plan governing detection and classification, containment, eradication, recovery, and notification.

 

14.2 As a service provider, MindShield notifies the affected Client without undue delay following confirmation of a personal data breach affecting that Client's data, and provides the information and support the Client requires to meet its own regulatory and contractual obligations.

 

14.3 Where MindShield is the accountable organization for affected data, MindShield notifies the Office of the Privacy Commissioner of Canada and affected individuals as required by applicable law.

 

14.4 MindShield maintains a breach register recording all breaches, including those not meeting a notification threshold.

 

14.5 Consistent with law-enforcement guidance, MindShield does not make ransom payments in the event of a ransomware attack, and cooperates with authorities and affected third parties as required.

 

15. Governance and Review

15.1 MindShield's privacy programme is owned by the Privacy Officer and approved by the Chief Executive Officer.

 

15.2 New features, integrations, data flows, and changes to AI providers or prompt architecture are subject to a Privacy Risk Review before release.

 

15.3 This Notice is reviewed at least annually, and sooner upon any material change to systems, data flows, or applicable regulation. When a material change is made, MindShield updates the version and effective date and notifies Clients.

 

16. Contact

Privacy Officer Blayne Kumar, Chief Operating Officer COGSEC SOLUTIONS INC (operating as MindShield™) blayne@mindshield.org

 

Participants should direct enquiries concerning their participation, their results, or the exercise of their rights to their own organization, which is the accountable organization for the assessment programme.

bottom of page