Legal

Security

This page covers the security of this website and how to report a vulnerability to us. The HyveMind platform has its own, much more detailed security page.

Last updated
August 13, 2026
Version
1.0
Entity
CogNoodle LLC (Wyoming, USA)

1. This website

cognoodle.ai is a set of pre-built static pages. Its attack surface is deliberately small.

  • No server-side application. There is no application server, no database, and no API behind this site. There is no login, no session, and no user account to compromise.
  • No stored personal data. The site holds no customer records. See our Privacy Policy for the small amount of data involved in simply serving a page.
  • No third-party scripts. We load no analytics, advertising, tag-manager, chat-widget, or tracking code, so there is no third-party supply-chain path into your browser through us.
  • Self-hosted fonts. Typefaces are bundled at build time and served from our own domain.
  • HTTPS everywhere. The site is served over TLS, with certificate management and edge protection handled by our hosting and content-delivery provider.

2. The HyveMind platform

Our product is a different system with a different risk profile: per-tenant database isolation, fail-closed authentication, encryption at rest, daily backups, and a candid account of what it does not have. That is documented on the platform site. If you are evaluating us as a vendor, read that page rather than this one.

3. How we work

  • Secrets and credentials are held in managed secret storage or an operating-system keychain and piped directly into the tools that need them, so values are not printed, written to files, or committed to source control.
  • Production changes are deployed from version control rather than from a laptop, so what is live corresponds to a reviewed commit.
  • We are a small team. Our security posture reflects that, and this page will grow as the company does.

4. Reporting a vulnerability

If you find a security issue in this website, in the HyveMind platform, or in anything else we operate, please tell us. Email security@cognoodle.ai with a description of the issue, the steps to reproduce it, the affected URL or component, and how you would like to be credited.

What we ask

  • Test only against your own data. Do not access, alter, or retain anyone else’s.
  • Stop at proof of concept — take no more data than is needed to demonstrate the issue.
  • No denial-of-service testing, no spam, no social engineering of our people or our providers, and no physical attacks.
  • Give us a reasonable opportunity to fix the issue before publishing it.

What you can expect

  • We aim to acknowledge a report within five business days and to keep you posted.
  • If you follow the guidelines above, we will treat your research as authorised, will not pursue legal action over it, and will say so if asked.
  • We do not currently pay bounties. We will credit you if you would like.

5. Contact

Security: security@cognoodle.ai. Legal and privacy: legal@cognoodle.ai.

CogNoodle LLC, a Wyoming limited liability company.