Security & Disclosure

Last Updated July 12, 2026Current Public Disclosure Policy

This policy names the public scope, current security posture, safe testing boundaries, and the route for reporting a vulnerability without creating additional harm.

Useful security research is reproducible, bounded, and quiet.

The goal is to give Cosmic Construct enough evidence to verify and fix a problem without turning the demonstration itself into an incident.

01

Current Security Posture

Cosmic Construct applies transport security, restrictive browser headers, server-side secret handling, bounded public inputs, payment-provider verification, least-privilege data access, dependency review, and human authority at commercial and technical commitment points.

This is a description of current safeguards, not a certification, audit opinion, warranty, or claim that compromise is impossible. Security requires continuing review as the business and website change.

02

Disclosure Scope

Reports may cover cosmicconstruct.tech and public API routes served from that domain. Third-party services such as Vercel, Supabase, Google, Stripe, carriers, domain registrars, and email providers are outside Cosmic Construct's testing authorization and should be reported through the provider's own program.

Development programs and concept systems shown on the website are not authorization to test physical equipment, private software, internal accounts, or non-public infrastructure.

03

How To Report

Email the affected URL, a concise description, reproducible steps, likely impact, and the minimum evidence needed to confirm the issue. Include a safe contact method and whether you believe customer data or an active payment path is at risk.

Do not send passwords, payment credentials, customer records, private keys, or unnecessary exploit payloads by email. Ask for a safer transfer method before sending sensitive evidence.

04

Good-Faith Testing Boundaries

  • Use the smallest number of requests and the least data necessary to demonstrate the issue.
  • Stop if testing exposes personal information, credentials, private business material, or instability.
  • Do not use denial of service, destructive payloads, malware, spam, credential attacks, social engineering, persistence, or physical intrusion.
  • Do not change, delete, download, retain, or disclose data that is not yours.
  • Do not test third-party accounts or infrastructure without that provider's written authorization.
05

Triage & Coordination

Cosmic Construct aims to acknowledge a useful report within five business days, then evaluate reproducibility, exploitability, affected data, operational impact, and provider coordination. Remediation timing depends on severity and the work needed to verify a safe fix.

Please allow a reasonable remediation period before public disclosure. Cosmic Construct may request coordinated timing when disclosure could increase risk to customers or providers.

06

Bounties, Safe Harbor & Law

No bug bounty, payment, employment offer, or formal legal safe harbor is promised unless Cosmic Construct provides it in writing. This policy does not authorize conduct prohibited by law or by a third party's terms.

Cosmic Construct will evaluate good-faith, non-destructive research in context and will not knowingly mischaracterize a compliant report as malicious. Researchers remain responsible for staying within the boundaries above.

07

Machine-Readable Contact

The current machine-readable disclosure contact is published at /.well-known/security.txt. The canonical website policy remains this page.

Policy Contact

Questions should be specific and easy to route.

Use the subject "Security Report." Do not send secrets or customer data. Ask for a safer transfer method when the minimum proof is sensitive.

make@cosmicconstruct.tech