Security and responsible disclosure
Trust is designed. In the code, too.
We build systems that organizations entrust with their processes and decisions. Here we explain how we protect this site, the principles behind how we design our products, and how to report a security issue to us.
This English version is provided for convenience. In case of any discrepancy, the Italian version prevails. Read the Italian version
- Reports
- info@cosen-lab.com
- Acknowledgment of receipt
- Within 5 business days
- security.txt
- Published (RFC 9116)
- Last reviewed
- October 2026
01Principles
Security as a requirement.
Not an add-on.
Our systems work alongside sensitive data and processes. That is why security is built into architectural decisions from the start, through four principles we apply to every project.
- 01
Least privilege
Every person and every system accesses only what is needed, for only as long as it is needed.
- 02
Bounded integration
Our systems work alongside our clients’ systems: read-only access or defined perimeters, where appropriate.
- 03
Human authority
Material decisions stay with people. Automation proposes; it does not decide silently.
- 04
Traceability
What matters must be reconstructable: who did what, when, and on the basis of which information.
02This site
The path of a request.
Protected at every step.
From your browser to our team: select a step to see which protections are active. We list only what is actually in operation.
Step 1 of 5 · What it receives
Your browser
- No cookies set by our server
- No advertising or analytics tracking tools
- Preferences (theme, consent) stored only in your browser
For security reasons, we describe the protections, not their parameters. The processing of personal data is described in the privacy policy.
03Report a vulnerability
Found an issue?
Tell us first.
We gratefully welcome reports made in good faith. Please write to us before making them public: it gives us time to protect the people who use the site.
- 01
You report
Describe the issue, how to reproduce it, and its possible impact.
- 02
We acknowledge
You will receive an acknowledgment of receipt within 5 business days.
- 03
We fix
We assess the severity, take action, and keep you updated on progress.
- 04
We thank you
If you wish, we will credit you among those who have contributed to the site’s security.
Message preview
To: info@cosen-lab.com
Subject: Security report · Website · severity: not sure
Hello, I would like to report a possible vulnerability (Website). Description: Affected URL or component: Steps to reproduce: Estimated impact: Perceived severity: Not sure I would like to be credited in the acknowledgments: yes / no Thank you
This page does not send or store anything. If you need an encrypted channel for the details, ask for one in your first message.
Our contact details are also published in the standard file/.well-known/security.txt
04Responsible disclosure rules
Good-faith research.
With clear rules.
If you follow these rules, we will consider your activity legitimate research and will not take legal action against you in connection with your report.
Scope
In scope
- The cosen-lab.com website and its pages
- The site interfaces used by the contact form
- Content and files published on the site
Out of scope
- Denial-of-service (DoS) attacks or load testing
- Social engineering, phishing, physical access
- Third-party services (e.g. Cloudflare, email providers)
- Automated scanner results without a demonstrated impact
- Mass submission of messages through the contact form
We ask you to
- Stop as soon as you have proof of the issue
- Use only your own accounts or data, or ones created for testing
- Give us time to fix it before discussing it publicly
- Delete any data obtained once your testing is complete
Not permitted
- Accessing, modifying, or retaining other people’s data
- Degrading or disrupting the service
- Exploiting the vulnerability beyond the minimum needed to demonstrate it
- Requesting payment in exchange for the information
There is currently no monetary rewards program (bug bounty).
05For clients
Evaluating a project with us? Let’s talk security now.
For organizations evaluating a pilot or an adoption, security is part of the qualification process: scope, data, roles, and responsibilities are defined before work begins.
Architecture
How the system integrates with yours and what stays separate.
On requestAccess and roles
Who sees what, who approves, and how it is tracked.
On requestQuestionnaires
We complete your vendor security questionnaires.
On request
Last reviewed: October 2026