Cogny · Vulnerability Disclosure

Cogny Vulnerability Disclosure

Vulnerability disclosure

Cogny runs a coordinated vulnerability disclosure program on Hackerone.

CompanyAi Enterprise SoftwareMarketingMarketing AnalyticsMarketing AutomationMCPAgentsData WarehouseAdvertising
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://cogny.com/security
checked: '2026-08-13'
program:
  published: true
  type: email-contact
  formal_policy: false
  page: https://cogny.com/security
  contact: privacy@cogny.com
  contact_uri: mailto:privacy@cogny.com
  statement: >-
    "If you have questions about our security practices or want to report a
    security concern, contact us at privacy@cogny.com."
  note: >-
    Cogny publishes a named channel for reporting security concerns on its
    public security page, so a researcher has a real address to reach. It is
    however the privacy alias rather than a dedicated security@ address, and
    there is no separate written disclosure policy.
security_txt:
  served: false
  probed:
  - url: https://cogny.com/.well-known/security.txt
    status: 404
  - url: https://app.cogny.com/.well-known/security.txt
    status: 404
  - url: https://api.cogny.com/.well-known/security.txt
    status: 521
  note: >-
    No RFC 9116 security.txt on any host. api.cogny.com could not be reached at
    all (Cloudflare 521, origin unreachable).
bug_bounty:
  program: null
  platform: null
  probed:
  - hackerone
  - bugcrowd
  - intigriti
  found: false
  note: No bug bounty or coordinated-disclosure program found on any platform.
gaps:
- id: no-security-txt
  detail: >-
    Serving /.well-known/security.txt on cogny.com and app.cogny.com with
    Contact, Policy, Preferred-Languages and Expires would make the existing
    reporting channel machine-discoverable. This is the cheapest remaining
    security-surface fix for Cogny.
- id: no-dedicated-security-alias
  detail: >-
    Security reports route to privacy@cogny.com. A dedicated security@cogny.com
    (or an alias documented as such) separates incident intake from GDPR/DSAR
    traffic.
- id: no-written-disclosure-policy
  detail: >-
    No safe-harbour statement, scope definition, or response-time commitment is
    published, so a researcher cannot tell what testing is authorised.
related:
- security/cogny-trust-center.yml
- well-known/cogny-well-known.yml