For security researchers

Find something? Tell us first. We'll fix it fast.

Cognielo operates on a responsible-disclosure policy. We read security@cognielo.com daily, respond within 48 hours, and credit researchers in the hall of fame below.

The deal

What we promise.

๐Ÿ“ฌ

Response in 48 hours

On weekdays. Critical issues (RCE, key disclosure, impersonation) get same-week remediation.

๐Ÿ›ก

No retaliation. Ever.

Reporting a flaw in good faith is a service to our users. We won't come after you legally or technically.

๐Ÿ†

Hall-of-fame credit

Opt-in public acknowledgment once a fix ships. Your byline + a link to your site or socials.

๐ŸŽ

Lifetime Pro for sev-1/sev-2

First 100 validated severity-1 or severity-2 reports earn a free lifetime Cognielo Pro subscription. Cash bounties once we're revenue-positive.

Scope

What's in. What's out.

In scope

Out of scope (please don't test)

Please don't

Timeline

Disclosure timeline.

DayWhat happens
0You email us a report at security@cognielo.com.
โ‰ค2We acknowledge receipt.
โ‰ค7We validate or ask for clarification.
โ‰ค30We share our remediation plan.
โ‰ค90We ship the fix. Critical issues: โ‰ค7 days.
+14You may publicly disclose โ€” or sooner with our coordination.
Credit

Hall of fame.

The first name here goes to whoever shows us something we missed. We'd rather pay you in Pro subscriptions and public credit than miss a real flaw.

Ready for your name

Email security@cognielo.com with a finding that ships in a fix. Opt-in credit.

Transparency

Our published threat model.

We maintain a STRIDE threat model covering every component Cognielo ships: the local substrate, the Anthropic API path, Cloudflare Workers, iCloud backups, widgets, and the Git pipeline. It names every residual risk we know about โ€” including the critical ones we're still closing before public launch.