Security and responsible disclosure

Trust is designed. In the code, too.

We build systems that organizations entrust with their processes and decisions. Here we explain how we protect this site, the principles behind how we design our products, and how to report a security issue to us.

This English version is provided for convenience. In case of any discrepancy, the Italian version prevails. Read the Italian version

Reports
info@cosen-lab.com
Acknowledgment of receipt
Within 5 business days
security.txt
Published (RFC 9116)
Last reviewed
October 2026

01Principles

Security as a requirement.
Not an add-on.

Our systems work alongside sensitive data and processes. That is why security is built into architectural decisions from the start, through four principles we apply to every project.

  1. 01

    Least privilege

    Every person and every system accesses only what is needed, for only as long as it is needed.

  2. 02

    Bounded integration

    Our systems work alongside our clients’ systems: read-only access or defined perimeters, where appropriate.

  3. 03

    Human authority

    Material decisions stay with people. Automation proposes; it does not decide silently.

  4. 04

    Traceability

    What matters must be reconstructable: who did what, when, and on the basis of which information.

02This site

The path of a request.
Protected at every step.

From your browser to our team: select a step to see which protections are active. We list only what is actually in operation.

Step 1 of 5 · What it receives

Your browser

  • No cookies set by our server
  • No advertising or analytics tracking tools
  • Preferences (theme, consent) stored only in your browser

For security reasons, we describe the protections, not their parameters. The processing of personal data is described in the privacy policy.

03Report a vulnerability

Found an issue?
Tell us first.

We gratefully welcome reports made in good faith. Please write to us before making them public: it gives us time to protect the people who use the site.

  1. 01

    You report

    Describe the issue, how to reproduce it, and its possible impact.

  2. 02

    We acknowledge

    You will receive an acknowledgment of receipt within 5 business days.

  3. 03

    We fix

    We assess the severity, take action, and keep you updated on progress.

  4. 04

    We thank you

    If you wish, we will credit you among those who have contributed to the site’s security.

1. Where is the issue?
2. How severe does it seem to you?

Message preview

To: info@cosen-lab.com

Subject: Security report · Website · severity: not sure

Hello, I would like to report a possible vulnerability (Website). Description: Affected URL or component: Steps to reproduce: Estimated impact: Perceived severity: Not sure I would like to be credited in the acknowledgments: yes / no Thank you

This page does not send or store anything. If you need an encrypted channel for the details, ask for one in your first message.

Our contact details are also published in the standard file/.well-known/security.txt

04Responsible disclosure rules

Good-faith research.
With clear rules.

If you follow these rules, we will consider your activity legitimate research and will not take legal action against you in connection with your report.

Scope

In scope

  • The cosen-lab.com website and its pages
  • The site interfaces used by the contact form
  • Content and files published on the site

Out of scope

  • Denial-of-service (DoS) attacks or load testing
  • Social engineering, phishing, physical access
  • Third-party services (e.g. Cloudflare, email providers)
  • Automated scanner results without a demonstrated impact
  • Mass submission of messages through the contact form

We ask you to

  • Stop as soon as you have proof of the issue
  • Use only your own accounts or data, or ones created for testing
  • Give us time to fix it before discussing it publicly
  • Delete any data obtained once your testing is complete

Not permitted

  • Accessing, modifying, or retaining other people’s data
  • Degrading or disrupting the service
  • Exploiting the vulnerability beyond the minimum needed to demonstrate it
  • Requesting payment in exchange for the information

There is currently no monetary rewards program (bug bounty).

05For clients

Evaluating a project with us? Let’s talk security now.

For organizations evaluating a pilot or an adoption, security is part of the qualification process: scope, data, roles, and responsibilities are defined before work begins.

  • Architecture

    How the system integrates with yours and what stays separate.

    On request
  • Access and roles

    Who sees what, who approves, and how it is tracked.

    On request
  • Questionnaires

    We complete your vendor security questionnaires.

    On request