Kosmos AI Labs · Vulnerability Disclosure

Kosmoslabs Vulnerability Disclosure

Vulnerability disclosure

Kosmos AI Labs publishes a named security contact and a response SLA, but no formal vulnerability disclosure policy, no safe-harbour language and no bug bounty. Recorded honestly: a reachable contact exists, a published VDP does not.

Kosmos AI Labs runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyOperational IntelligenceObservabilityOpenTelemetryIncident ManagementRoot Cause AnalysisAIOpsEnterprise Software
Program: Hackerone

Disclosure Policy

Security Contact

Contact
descriptionDedicated security alias published on the security page. Questionnaires and DPA requests are routed here with a five-business-day SLA. The alias is presented for security correspondence generally; no dedicated vulnerability-intake process is described.
Contact
emailsecurity@kosmoslabs.ai
Contact
sourcehttps://kosmoslabs.ai/resources/security/

Source

Vulnerability Disclosure

kosmoslabs-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: probed
source: >-
  https://kosmoslabs.ai/resources/security/, https://trust.kosmoslabs.ai/, plus /.well-known/
  probes across all Kosmos hosts on 2026-07-19
description: >-
  Kosmos AI Labs publishes a named security contact and a response SLA, but no formal
  vulnerability disclosure policy, no safe-harbour language and no bug bounty. Recorded honestly:
  a reachable contact exists, a published VDP does not.

policy_published: false
policy_url: null
safe_harbor: false
bug_bounty:
  program: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  result: no program found

security_txt:
  present: false
  probed_hosts:
  - kosmoslabs.ai
  - docs.kosmoslabs.ai
  - app.kosmoslabs.ai
  - ingest.kosmoslabs.ai
  status: 404 on every host
  probed: '2026-07-19'
  detail: well-known/kosmoslabs-well-known.yml

contact:
  email: security@kosmoslabs.ai
  description: >-
    Dedicated security alias published on the security page. Questionnaires and DPA requests are
    routed here with a five-business-day SLA. The alias is presented for security correspondence
    generally; no dedicated vulnerability-intake process is described.
  source: https://kosmoslabs.ai/resources/security/

published_security_surface:
  security_page: https://kosmoslabs.ai/resources/security/
  trust_center: https://trust.kosmoslabs.ai/
  security_overview_doc: https://docs.kosmoslabs.ai/product-documentation/security-overview
  note: >-
    These pages document security posture (encryption, integration scopes, control program,
    penetration testing) rather than a researcher-facing disclosure policy.

gaps:
- No published vulnerability disclosure policy or reporting instructions.
- No /.well-known/security.txt on any host.
- No safe-harbour / legal-protection statement for researchers.
- No bug bounty program.
- No stated triage or remediation timeline for reported vulnerabilities.