Security

Security

Last reviewed:

What is actually in place

Only implemented, continuously operating controls are listed here. Cohesive is a one-person product, so this page states what is true rather than what sounds reassuring.

This website and the waitlist

The backend

What is not claimed

Report a vulnerability

Email [email protected] with “security” in the subject line. Reports are read by a person, acknowledged within 3 working days, and you will be kept informed until the issue is closed. Credit is given if you want it.

Useful in a report: what you found, the steps to reproduce it, the affected URL or endpoint, and what an attacker could achieve. A proof of concept helps.

Please do not run automated scanners or load tests against the production site, attempt denial of service, brute-force the signup form, access or modify data belonging to anyone else, or use social engineering against anyone. If you find data belonging to another person, stop, do not download it, and tell us what you saw.

Do not include secrets, credentials, or unnecessary personal data in your report — not yours and not anyone else’s.

Research conducted in good faith and within those limits is welcome, and no legal action will be pursued over it. If you are unsure whether something is in scope, ask first.

Incidents

There is no public status page yet; if one is added it will be linked here. If a security incident affects your personal data, you will be told directly, along with what happened, what it means for you, and what has been done — within the 72-hour window the GDPR requires for notifying the supervisory authority, and without waiting for a complete post-mortem before telling you something.