Security and vulnerability disclosure
Effective: October 6, 2026
Reporting a vulnerability
If you believe you've found a security vulnerability in this website or in software we've delivered, please email security@cotangentinc.com. Include:
- the affected site, application, or component;
- a description of the issue and its potential impact; and
- the steps needed to reproduce it.
Our contact details are also published in machine-readable form at /.well-known/security.txt.
What to expect
- We'll acknowledge your report within three business days.
- We'll investigate, keep you informed of our progress, and tell you when the issue is resolved.
- With your permission, we'll credit you for the discovery.
Good-faith research
We won't pursue legal action against anyone who reports a vulnerability in good faith and follows these guidelines:
- Access, change, or delete no more data than is needed to demonstrate the issue.
- Don't degrade service: no denial-of-service tests, spam, or automated scanning at high volume.
- Don't use social engineering, phishing, or physical attacks.
- Give us a reasonable time to fix the issue before disclosing it publicly.
Systems owned by our clients, including government systems, are covered by their owners' own policies. Report issues in those systems through the owner's disclosure program.