Cognielo operates on a responsible-disclosure policy. We read security@cognielo.com daily, respond within 48 hours, and credit researchers in the hall of fame below.
On weekdays. Critical issues (RCE, key disclosure, impersonation) get same-week remediation.
Reporting a flaw in good faith is a service to our users. We won't come after you legally or technically.
Opt-in public acknowledgment once a fix ships. Your byline + a link to your site or socials.
First 100 validated severity-1 or severity-2 reports earn a free lifetime Cognielo Pro subscription. Cash bounties once we're revenue-positive.
elo-core Rust crate)| Day | What happens |
|---|---|
| 0 | You email us a report at security@cognielo.com. |
| โค2 | We acknowledge receipt. |
| โค7 | We validate or ask for clarification. |
| โค30 | We share our remediation plan. |
| โค90 | We ship the fix. Critical issues: โค7 days. |
| +14 | You may publicly disclose โ or sooner with our coordination. |
The first name here goes to whoever shows us something we missed. We'd rather pay you in Pro subscriptions and public credit than miss a real flaw.
Email security@cognielo.com with a finding that ships in a fix. Opt-in credit.
We maintain a STRIDE threat model covering every component Cognielo ships: the local substrate, the Anthropic API path, Cloudflare Workers, iCloud backups, widgets, and the Git pipeline. It names every residual risk we know about โ including the critical ones we're still closing before public launch.