Cognizant Technology Solutions · Vulnerability Disclosure

Cognizant Technology Vulnerability Disclosure

Vulnerability disclosure

Cognizant Technology Solutions runs a coordinated vulnerability disclosure program on Hackerone.

AI PlatformConsultingDigital TransformationIT ServicesMulti-AgentNeuro AIFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-05'
method: searched
source: https://hackerone.com/cognizant
note: >-
  Cognizant runs TWO distinct, independently verified disclosure channels — a corporate-wide
  HackerOne Vulnerability Disclosure Program, and a separate project-level security policy for
  the Cognizant AI Lab open-source repositories. Both are recorded because they route to
  different teams and an agent (or a researcher) needs to pick the right one.
  Verified with a control probe: hackerone.com/cognizant returned HTTP 200 with a real program
  profile photo and og:title "Cognizant - Vulnerability Disclosure Program | HackerOne", while
  a deliberately nonexistent handle (hackerone.com/cognizant-nonexistent-zzz9) returned 404
  with no profile photo. The 200 is a live program, not a platform catch-all.
programs:
- name: Cognizant Vulnerability Disclosure Program
  type: vulnerability-disclosure-program
  platform: hackerone
  url: https://hackerone.com/cognizant
  scope: corporate
  bounty: false
  bounty_note: >-
    Listed by HackerOne as a Vulnerability Disclosure Program rather than a Bug Bounty
    Program. No award amounts were published on the public program page; recorded as
    no-bounty rather than assumed.
  evidence:
    url: https://hackerone.com/cognizant
    http_status: 200
    og_title: 'Cognizant - Vulnerability Disclosure Program | HackerOne'
    control_probe:
      url: https://hackerone.com/cognizant-nonexistent-zzz9
      http_status: 404
    fetched: '2026-09-05'
  page_note: >-
    The program page is a JavaScript-rendered single-page app; program policy text and scope
    tables are not present in the served HTML. Presence and identity were established from
    the server-rendered OpenGraph metadata, not from the SPA body.
- name: Cognizant AI Lab open-source security policy
  type: security-policy
  platform: github
  url: https://github.com/cognizant-ai-lab/neuro-san/blob/main/SECURITY.md
  scope: cognizant-ai-lab repositories (neuro-san and siblings)
  contact: labgithub@cognizant.com
  channel: email
  public_issues_prohibited: true
  acknowledgement_sla: 48 hours
  disclosure_model: coordinated — public disclosure after a fix is released
  supported_versions:
    latest: supported
    older: unsupported
    detail: >-
      The policy supports only the latest release and explicitly marks anything below it
      unsupported. This is also the closest thing the project publishes to a version support
      policy — see lifecycle/cognizant-technology-lifecycle.yml.
  evidence:
    url: https://raw.githubusercontent.com/cognizant-ai-lab/neuro-san/main/SECURITY.md
    http_status: 200
    fetched: '2026-09-05'
security_txt:
  served: false
  detail: >-
    /.well-known/security.txt returned 404 on both cognizant.com and www.cognizant.com. Neither
    disclosure channel above is discoverable from the domain root, which is the one gap worth
    reporting back to the provider: an RFC 9116 security.txt pointing at the HackerOne program
    would make an existing, working program machine-discoverable at zero cost.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cognizant-technology-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.