Vulnerability Disclosure Policy
Last updated: 5th August 2026
Cogliva welcomes good-faith reports of suspected security vulnerabilities affecting its publicly available services. This page explains how to submit a report and how such reports may be handled.
Purpose
We would rather hear about a suspected security issue than not. This policy gives researchers, customers and other users a clear, practical way to tell us about one.
This policy is guidance only. It does not create a contract, a service-level agreement, or an obligation for Cogliva to investigate, respond to, or remediate any particular submission.
How to report a suspected vulnerability
Send reports to security@cogliva.com. Where reasonably available, please include:
- The affected public page, URL, feature or service
- A clear description of the suspected vulnerability
- Steps sufficient to understand or reproduce the issue
- The potential impact
- Supporting screenshots or technical evidence
- Contact details, if you are willing to be contacted
Please do not include in your report:
- Passwords or access tokens
- Unnecessary personal or customer information
- Large data extracts
- Confidential information obtained beyond what was minimally necessary to identify the issue
Incomplete, automated, spam-like or unverifiable reports may not receive an individual response.
Scope
This policy applies to publicly accessible websites, applications and services owned and operated by Cogliva.
Third-party services, integrations and platforms that Cogliva does not control may fall outside this policy and may need to be reported directly to the relevant provider.
Good-faith security research
If you are looking at a suspected issue, please:
- Avoid harming users or disrupting services
- Test only what is reasonably necessary to confirm the issue
- Stop if you encounter personal, confidential or customer data
- Avoid downloading, retaining, modifying or deleting data
- Avoid privacy violations
- Avoid escalating access beyond what is necessary to demonstrate the issue
- Allow Cogliva a reasonable opportunity to consider the report before any public disclosure
- Keep the issue confidential while Cogliva considers whether investigation or remediation is appropriate
Nothing here should be read as authorisation for unrestricted testing of Cogliva services.
Prohibited activities
The following are not permitted under this policy:
- Denial-of-service, service-degradation or destructive testing
- Deploying malware
- Social engineering, phishing or physical security testing
- Credential stuffing, brute-force attacks, password spraying, or testing with stolen or leaked credentials
- Accessing or attempting to access another user's account
- Data extraction or establishing persistent access
- Large-scale automated scanning that could affect availability, or high-volume automated submissions
- Any activity that violates applicable law
- Any activity that creates risk for Cogliva, its users, customers, suppliers or service providers
How Cogliva may handle reports
Cogliva is a small, AI-first business. We handle reports pragmatically rather than through a formal programme:
- We may review reports that appear credible, relevant and sufficiently detailed
- We may contact the reporter if further information is needed
- We may prioritise reports based on apparent severity, impact, reproducibility and available resources
- We may conclude that a report is not valid, not in scope, not reproducible, already known, or not suitable for further action
- We may not be able to respond individually to every submission
- Response and review times may vary depending on severity, complexity and available resources
- Investigation, mitigation and remediation decisions and timelines remain at Cogliva's discretion
The absence of a response should not be taken as confirmation that a vulnerability exists, or that a report has been accepted. Nothing in this policy creates a guaranteed response or remediation timeline.
No bug bounty
Cogliva does not currently operate a paid bug-bounty programme. Submitting a report does not create any entitlement to payment, compensation, reimbursement, reward or recognition, and researchers should not incur expenses expecting reimbursement.
We may choose to acknowledge a helpful contribution, but no acknowledgement is promised.
Legal position
Cogliva supports legitimate, good-faith reporting carried out in accordance with this policy. Cogliva does not intend to pursue action solely because a person submits a good-faith report in accordance with this policy.
This does not limit Cogliva's rights where conduct exceeds what is reasonably necessary, affects other users or systems, violates applicable law or third-party terms, or otherwise falls outside this policy. No rights are waived, and nothing here authorises unlawful activity or the violation of anyone's privacy.
Coordinated disclosure
Please do not publicly disclose a suspected vulnerability before Cogliva has had a reasonable opportunity to consider the report.
Any eventual public disclosure should not expose user data, customer information, credentials, technical secrets, or instructions that would materially increase security risk for others.
Limitations and policy status
This policy may be changed, suspended or withdrawn at any time. It does not create an employment, agency, partnership, fiduciary or contractual relationship, and it does not create a duty to investigate, respond, remediate, compensate, or provide updates. Cogliva manages reports based on risk, relevance and available resources.
Reporters are responsible for complying with all applicable laws.
Related pages
See the Trust Center for security and responsible-AI information, the Privacy Policy for how personal data is handled, and the Terms of Service for the agreement governing use of Cogliva.