Skip to content
United States · Delivery record

Engineering for US companies.

The largest market for outsourced engineering in the world, and the most sceptical — for good reason. What settles a US vendor review is not a rate card but evidence: an audited information security management system, IP assigned on payment, and a written scope before anyone writes code. All three are published, not negotiated.

Working with us from the USUS
Daily overlap
09:00–12:30 ET (shifted)
Contract currency
USD
Data regime
CCPA / CPRA, plus state privacy statutes
Regulator
California Privacy Protection Agency and state attorneys general
Working language
English
§ 01Working with the US

Hours, money,
and paperwork.

The three things that decide whether a cross-border engagement works, answered before you ask. Everything here is specific to the US rather than a global average.

Time overlap

09:00–12:30 ET (shifted)

Stated exactly, because the arithmetic matters. Our standard day is 10:00–18:00 IST, which is 23:30–07:30 ET — no natural overlap with a US working day at all. So engineers on a US engagement work a shifted day to hold 09:00–12:30 ET, which is 19:30–23:00 IST. That is a staffing commitment written into the engagement, not a best-effort. Standups, reviews and demos sit inside it; everything else runs on written reporting. West Coast teams take the same window at 06:00–09:30 PT.

Currency and tax

USD

Quoted and invoiced in US dollars via wire transfer or online gateway. Indian tax does not reach your invoice — exported services are zero-rated at source. We are not a US entity, so no US sales tax is charged either. Your finance team will usually want a Form W-8BEN-E on file for withholding purposes, which we provide before the first invoice rather than after it.

Data protection

Governing law
CCPA / CPRA, plus state privacy statutes
Authority
California Privacy Protection Agency and state attorneys general
Our role
Processor, on your instructions

Named sub-processors, written consent before any addition.

We act as a service provider rather than a third party under CCPA/CPRA: your data is processed only on your instructions, never sold, and never shared for cross-context behavioural advertising. Where an engagement touches health data we work to a HIPAA business associate agreement, and where it touches cardholder data we scope to PCI DSS boundaries agreed in writing before build.

§ 02What your procurement will ask

Answered
before you ask.

The questions we are asked most often from the US, answered straight. Where we do not hold something, it says so.

SOC 2 report

We hold ISO 27001:2022, not SOC 2. The control families overlap substantially, and most US reviewers accept ISO 27001 with a mapped control summary — which we provide. If your policy requires SOC 2 specifically, we will say so before you spend time on a review rather than after.

Security questionnaire

Completed in full, typically within three working days, with the ISO 27001 certificate number so a reviewer can verify it independently. We do not answer 'in progress' to a control we have not implemented.

IP assignment and work-for-hire

Custom code, designs and infrastructure definitions assign to you on payment. Pre-existing Cognimit libraries are licensed perpetually and non-exclusively for that product. Open-source components stay under their own licences, listed in a manifest at handover.

Insurance and indemnities

Professional indemnity and cyber cover are confirmed at contract, with limits stated in the MSA rather than described vaguely. Mutual indemnities for IP infringement and confidentiality breach are standard.

  • ISO 9001:2015 Quality Management System — certified company. Certificate 706564/2026/R, issued by Robust Certifications Pvt. Ltd.Quality Management SystemsCertified CompanyISO9001:2015
  • ISO 27001:2022 Information Security Management System — certified company. Certificate 25-07-21156763, issued by Anglia Compliance Group.Information Security ManagementCertified CompanyISO27001:2022
  • ISO 20000-1:2018 IT Service Management System — certified company. Certificate 25-07-21156764, issued by Anglia Compliance Group.IT Service Management SystemsCertified CompanyISO20000-1:2018

Certificate numbers, accreditation status and the verification route are published on our trust page. Check them without asking us.

§ 03What the US asks us for

The problems
that arrive.

The work that comes to us from the US most often. If one of these is yours, send us the brief.

01

Series A to C platform work

A first product that found traction on architecture that will not carry the next order of magnitude. The work is usually re-platforming a monolith into service boundaries without stopping shipping.

02

AI moved from demo to production

A model behind an internal prototype that now needs evaluation harnesses, cost and latency budgets per call path, and outputs traceable to a source before legal will sign off.

03

Team extension without a US hire

A US engineering lead who needs three more engineers this quarter and cannot fund three US salaries. Named engineers inside your repository on a monthly allocation, no recruitment fee.

Why the US works with us

  • ISO 27001:2022 with a published certificate number, verifiable with a UK certification body without contacting us — most offshore vendors offer a policy document instead.
  • A written recommendation covering scope, non-scope, model and cost within three to five working days of a brief, not after four discovery calls.
  • We operate three software products of our own, so the standard we describe is one we already live with at 03:00 when something breaks.
Where we are not the right answer

We have no US entity, no US office and no US bank account. Contracts are cross-border with India as the governing jurisdiction unless we agree otherwise. And the overlap is bought, not free: it exists because engineers work a shifted evening in India, which is three and a half hours a day, not a shared one. If your procurement requires a domestic supplier, or your team needs all-day live availability, we are the wrong answer and will tell you on the first call.

§ 04United States · Questions

Asked from
the US.

Answers open with the answer. The general set — pricing, process, IP, security — is on the FAQ.

Do you have a SOC 2 report?
No. We hold ISO 27001:2022, certificate 25-07-21156763, independently audited by Anglia Compliance Group in the UK. The two frameworks overlap heavily and most US reviewers accept ISO 27001 with a control mapping, which we supply. If your policy names SOC 2 specifically, we will tell you at the first call rather than after a review cycle.
How does the time difference work with a US team?
India is ten and a half to thirteen and a half hours ahead of the United States depending on your coast, which means a standard Indian working day has zero overlap with yours. We solve it by staffing rather than by hoping: engineers assigned to a US engagement work a shifted day covering 09:00–12:30 ET, equal to 19:30–23:00 IST, and that shift is named in the engagement. Anyone who tells you a standard Indian day overlaps US business hours has not done the arithmetic.
What stops us being locked in if the relationship ends?
Ownership of the accounts, not just the code. Wherever possible your repositories, cloud accounts, domains and third-party service subscriptions are created in your name from day one, so there is nothing to transfer because nothing was ever ours. Every engineer who touches the work is under a written assignment to Cognimit, which is what makes our assignment to you enforceable rather than nominal — a gap that often catches contracts made with individual freelancers. Escrow can be arranged where your risk register calls for it. Runbooks and architecture notes are contractual deliverables, so continuity does not depend on us answering the phone.
Can you sign a HIPAA business associate agreement?
Yes, where the engagement genuinely touches protected health information. The BAA is signed before any PHI is exchanged, access is limited to named engineers on the engagement, and the data residency region is fixed in the agreement rather than assumed.
§ 05Other markets

Where else
we work.

Working hours, currency and data protection, covered for every market we serve.

Working with the US.

Contracted in USD, governed by CCPA / CPRA, plus state privacy statutes, delivered inside the 09:00–12:30 ET (shifted) overlap window.

Cognimit Technologies LLP · Monday to Friday, 10:00–18:00 IST · IST (UTC+5:30)

WhatsAppStart a chat