RESPONSIBLE DISCLOSURE

Security at Cognita

We're building the audit trail for AI compliance. That promise depends on operating one ourselves — so when you find something we missed, we want to hear about it.

How to report

Pick whichever channel fits the urgency. We respond to all inbound within one business day.

Email
Request a PGP key in your first email; we'll respond with the current fingerprint
HackerOne
In private beta — request scope at [email protected]
Bounties paid through the H1 platform
security.txt
/.well-known/security.txt
Machine-readable per RFC 9116
In-app report
Settings → Security → Report a vulnerability
Authenticated reporters get a tenant-isolated thread

Scope

What we ask

What you can expect

Hall of fame

Researchers who've helped us catch real issues. Listed with permission.

The wall is empty for now — the program just opened. Find something? You'll be the first.

Out of scope

Back to home