Legal
Security
This page covers the security of this website and how to report a vulnerability to us. The HyveMind platform has its own, much more detailed security page.
- Last updated
- August 13, 2026
- Version
- 1.0
- Entity
- CogNoodle LLC (Wyoming, USA)
1. This website
cognoodle.ai is a set of pre-built static pages. Its attack surface is deliberately small.
- No server-side application. There is no application server, no database, and no API behind this site. There is no login, no session, and no user account to compromise.
- No stored personal data. The site holds no customer records. See our Privacy Policy for the small amount of data involved in simply serving a page.
- No third-party scripts. We load no analytics, advertising, tag-manager, chat-widget, or tracking code, so there is no third-party supply-chain path into your browser through us.
- Self-hosted fonts. Typefaces are bundled at build time and served from our own domain.
- HTTPS everywhere. The site is served over TLS, with certificate management and edge protection handled by our hosting and content-delivery provider.
2. The HyveMind platform
Our product is a different system with a different risk profile: per-tenant database isolation, fail-closed authentication, encryption at rest, daily backups, and a candid account of what it does not have. That is documented on the platform site. If you are evaluating us as a vendor, read that page rather than this one.
3. How we work
- Secrets and credentials are held in managed secret storage or an operating-system keychain and piped directly into the tools that need them, so values are not printed, written to files, or committed to source control.
- Production changes are deployed from version control rather than from a laptop, so what is live corresponds to a reviewed commit.
- We are a small team. Our security posture reflects that, and this page will grow as the company does.
4. Reporting a vulnerability
If you find a security issue in this website, in the HyveMind platform, or in anything else we operate, please tell us. Email security@cognoodle.ai with a description of the issue, the steps to reproduce it, the affected URL or component, and how you would like to be credited.
What we ask
- Test only against your own data. Do not access, alter, or retain anyone else’s.
- Stop at proof of concept — take no more data than is needed to demonstrate the issue.
- No denial-of-service testing, no spam, no social engineering of our people or our providers, and no physical attacks.
- Give us a reasonable opportunity to fix the issue before publishing it.
What you can expect
- We aim to acknowledge a report within five business days and to keep you posted.
- If you follow the guidelines above, we will treat your research as authorised, will not pursue legal action over it, and will say so if asked.
- We do not currently pay bounties. We will credit you if you would like.
5. Contact
Security: security@cognoodle.ai. Legal and privacy: legal@cognoodle.ai.
CogNoodle LLC, a Wyoming limited liability company.