Security and disclosure protocol.

This draft page documents intended site security practices, machine-readable endpoint boundaries, and vulnerability reporting flow.

  • Operational draft
  • Security review required
  • Account owner review required

Operational Draft // Legal Review Required

This page is launch security copy. Final safe harbor, response timelines, bounty posture, reporting mailbox, and third-party testing boundaries require AJ, legal, and security owner approval.

  • Confirm security reporting mailbox
  • Confirm vulnerability response owner
  • Confirm safe harbor and bounty posture

Security Controls

Security Baseline

Cosmic Construct intends to use secure transport, least-privilege access, dependency review, logging, and deployment review for public site operations.

Agent Surfaces

Machine-readable endpoints should remain public, narrow, documented, and non-sensitive. Any write action must require human review.

Report Channel

Responsible disclosure should route to an approved inbox with clear triage ownership before this policy is final.

Disclosure Flow

Security reports should be precise, non-destructive, and easy to reproduce by an accountable owner.

Report Security Issue

01 Report

Send a concise report with affected URL, reproduction steps, impact, evidence, and contact information.

02 Triage

Cosmic Construct reviews severity, exploitability, data exposure, and operational impact.

03 Contain

The team coordinates remediation, temporary controls, communication, and account review as needed.

04 Resolve

Fixes are verified before public detail is shared. Timing depends on severity, vendor coordination, and customer risk.

05 Close

Reporter and internal records are updated with final disposition, lessons learned, and follow-up controls.

Out Of Scope

  • Denial of service, spam, phishing, malware, credential attacks, social engineering, or destructive testing
  • Accessing, changing, deleting, or exfiltrating data that is not yours
  • Testing third-party services, payment processors, carriers, or accounts without written authorization
  • Physical attacks, facility probing, or attempts to bypass safety controls

Security Contact

Use the general contact channel until a dedicated security inbox is approved.

make@cosmicconstruct.tech

Do not include secrets, customer data, or exploit payloads beyond what is necessary to reproduce the issue safely.