Skip to content
cognatory
Home

Effective July 24, 2026

Responsible disclosure policy

We welcome good-faith reports that help us protect Cognatory and the wider community. This policy authorizes limited security research on the systems identified below when you follow these rules.

Contact

Email security@cognatory.com with:

  • the affected asset and vulnerability type;
  • clear reproduction steps and demonstrated impact;
  • relevant logs, screenshots, or proof-of-concept code; and
  • a safe way to contact you.

Do not include personal data, credentials, or other sensitive information unless necessary to explain the issue. If sensitive material is necessary, ask us to arrange an appropriate transfer method before sending it.

We aim to acknowledge a report within five business days. Investigation and remediation time will vary. Please give us a reasonable opportunity to investigate before public disclosure.

Scope

This policy applies only to cognatory.com and its subdomains when they are demonstrably operated by Cognatory. A third-party service merely linked from, embedded in, or used by Cognatory is not in scope unless we expressly identify it as such.

Research rules

To remain within this policy:

  • make a good-faith effort to avoid privacy violations, data loss, service disruption, and harm to others;
  • use only accounts and data you own or have explicit permission to use;
  • access only the minimum information needed to demonstrate the issue, then stop and report it;
  • do not retain, copy, alter, destroy, or publicly disclose data you encounter;
  • do not establish persistence, pivot to other systems, or use a vulnerability to access communications;
  • do not perform denial-of-service, resource-exhaustion, high-volume automated scanning, spam, social engineering, phishing, physical intrusion, or supply-chain attacks;
  • do not extort, threaten, or condition disclosure on payment; and
  • comply with applicable law.

Out of scope

Examples include findings based only on missing best-practice headers without demonstrated impact, version banners, self-XSS, clickjacking on pages with no sensitive action, automated scanner output without validation, denial-of-service, and issues solely in third-party systems.

Our commitment

If you comply with this policy, Cognatory will consider your research authorized under this policy and will not initiate legal action against you for that research. If a third party initiates legal action, we will make known that your activity complied with this policy. We cannot authorize activity on third-party infrastructure, waive the rights of others, or bind law-enforcement authorities.

If you are unsure whether an action is permitted, ask before proceeding. This is a disclosure program, not a bug-bounty program; we do not promise payment, credit, or other compensation.

© 2026 Cognatory LLC.
PrivacyTermsDisclosureAccessibility