Website security · attested scope

What this website does with your data.

This page describes the public Cognate Labs website and its inquiry forms. Product or client deployments require their own security and data-processing terms.

Forms and delivery

The contact and BVI waitlist forms collect only the fields shown. Submissions are validated on the server and delivered by email through Resend. API credentials stay on the server and are not included in browser code. Hidden honeypot fields suppress simple automated submissions.

Transport and application controls

The site is served over HTTPS with HTTP Strict Transport Security. Form payloads have type and length checks before delivery. The public website does not expose an account system, customer database, or browser-side API key.

Claims we are not making

Cognate Labs does not claim a security certification on this page. This notice does not imply that a future BVI or client deployment uses the same architecture, retention policy, subprocessors, or data boundary. Those details belong in the agreement for that system.

Report a concern

Send a concise report to hello@cognatelabs.io. Do not include secrets, credentials, or personal data that are not necessary to explain the concern.