Back to home

Vulnerability Disclosure Policy

How security researchers can report a vulnerability to us, and what we commit to in response.

v1.1, 28 September 2026We are continuing to refine these documents based on customer feedback and ongoing review.

Vulnerability Disclosure Policy

Network Sunday Global Limited (company number 07832813, trading as CogniScale)

Registered office: Queensbury House, 106 Queens Road, Brighton, BN1 3XF.

Effective from: 1 June 2026 (v1); accuracy-corrected 28 September 2026 (v1.1)

This is v1.1, corrected 28 September 2026.

We take the security of the Formula AI Control Centre seriously. If you believe you've found a security vulnerability in our platform, CogniScale Helper, or any service we operate, we'd like to hear from you. This policy explains how to tell us, what we'll do, and what we ask of you.


1. How to report

Email: [email protected]

Please include:

  • A clear description of the vulnerability
  • Step-by-step instructions to reproduce it (where applicable)
  • The version of the Service or component affected (URL, CogniScale Helper version, etc.)
  • Any proof-of-concept code or screenshots (please do not include exploit payloads that would actually run against a live system)
  • Your contact details if you'd like attribution or follow-up

For sensitive reports, email [email protected] and ask us for a secure transfer method before sending anything sensitive.


2. What we commit to

When you report a vulnerability in good faith:

  • We will acknowledge your report and agree a response timetable with you under this policy
  • Public credit in our advisory or release notes, if you would like it
  • No legal action against you for good-faith research conducted under this policy (see the safe harbour below)

We are a small team; ask us to confirm current mailbox ownership and response times before relying on a specific clock.


3. Scope

The following are in scope for this disclosure policy:

  • The CogniScale website (cogniscale.com and subdomains)
  • The Formula AI Control Centre platform (app.cogniscale.com)
  • CogniScale Helper
  • Our published APIs

The following are out of scope (please do not test these directly):

  • Third-party infrastructure or services not operated by CogniScale. Please report issues with AI model providers directly to those providers.
  • Sub-processors' own infrastructure (Supabase, Railway, GitHub, Netlify, Stripe and the other services on our sub-processor list at https://cogniscale.com/sub-processors, which have their own programmes)
  • Customer organisation accounts other than your own (do not test against another customer's data)
  • Social engineering attacks against CogniScale staff
  • Physical attacks against CogniScale offices or staff

4. What's a vulnerability, and what isn't

Examples of in-scope vulnerabilities:

  • Cross-site scripting, SQL injection, or other OWASP Top 10 web application flaws
  • Authentication or authorisation bypasses
  • Information disclosure of customer data or credentials
  • Server-side request forgery
  • Remote code execution
  • Vulnerabilities in CogniScale Helper that could be exploited from the network or a malicious local document
  • Prompt-injection or RAG-poisoning flaws that bypass our agentic AI safety controls
  • Cryptographic implementation flaws
  • Race conditions that lead to data exposure

Generally NOT considered vulnerabilities (please don't report these unless you can demonstrate a concrete impact):

  • Missing best-practice security headers without a concrete exploit
  • Self-XSS that requires the victim to paste content into their own browser
  • Reports from automated scanners without a demonstrated exploit
  • Banner-grabbing, version disclosure of public software
  • Brute-force attacks on rate-limited endpoints
  • Issues that only affect outdated browsers
  • Lack of CSRF on form actions that have no side effects
  • Theoretical issues without a proof of concept

5. Safe harbour for good-faith research

If you act in good faith and within the scope of this policy:

  • We will not pursue legal action against you, including under the Computer Misuse Act 1990, the Data Protection Act 2018, the Investigatory Powers Act 2016, or any related civil or criminal cause of action
  • We will not enforce restrictive terms of service against you (such as our acceptable-use policy) for the specific research activity that brought the issue to light
  • We will treat your research as authorised for the purposes of any criminal or civil law that requires authorisation, to the extent we are able to do so

This safe harbour applies provided that you:

  • Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the Service
  • Only interact with your own accounts or accounts you have explicit permission from the account holder to test
  • Do not exfiltrate data beyond the minimum needed to demonstrate the vulnerability
  • Do not disclose the vulnerability publicly before we've had a reasonable opportunity to remediate (we'll agree a coordinated disclosure timeline together)
  • Comply with applicable law

If you're unsure whether something is in scope, please ask before testing.


6. What we ask you not to do

  • Don't disclose publicly before we've had a chance to fix the issue. Co-ordinated disclosure protects users.
  • Don't degrade the Service. Please don't perform load tests, DDoS or anything that affects availability.
  • Don't access more data than needed to demonstrate the vulnerability. If you discover sensitive data, stop, secure your copy, and let us know.
  • Don't extort or threaten. Reports demanding payment in exchange for not disclosing are not eligible for safe harbour.
  • Don't violate the privacy of CogniScale customers, staff, or anyone else. Use only your own test accounts or accounts you have permission to test.

7. Bug bounty

We are not currently running a paid bug-bounty programme. We may launch one in the future, in which case the terms will be published at https://cogniscale.com/security/bug-bounty.

We do offer public credit and (where appropriate) a thank-you in our security advisories for researchers who have helped us improve the Service.


8. Reporting other security issues

For security issues that are not vulnerabilities, such as phishing emails impersonating CogniScale, suspected account compromise or accidental exposure of credentials in a public location, email [email protected]. We will direct the report to the right person.

For customer support issues (a feature isn't working as expected, a billing question, an account login problem), use the contact route shown in the application, not this policy. Those aren't security issues.


9. Updates to this policy

We may update this policy from time to time as our processes mature. The latest version is always at https://cogniscale.com/security/disclosure. Material changes will be announced in our changelog.


Document control

FieldValue
Versionv1.1, 28 September 2026 accuracy correction
Effective from1 June 2026 (v1); accuracy-corrected 28 September 2026 (v1.1)
Change logv1.1, 28 September 2026: added company details, clarified the Helper description and reporting scope, and replaced fixed response times with an agreed timetable.
OwnerNetwork Sunday Global Limited (company number 07832813, trading as CogniScale)
Registered officeQueensbury House, 106 Queens Road, Brighton, BN1 3XF
Contact[email protected]
Next reviewTo be confirmed