Data boundaries
Define approved sources, data classes, retention, provider exposure, and prohibited uses for the engagement.
Cognelyra incorporates security, privacy, responsible-AI, and governance requirements into solution design and delivery—aligned to each client’s policies, risk profile, and applicable obligations.
Ask a trust questionCognelyra does not claim public certifications or universal compliance on this site. Engagement requirements, evidence, controls, and responsibilities are established for the specific client, solution, and delivery environment.
Define approved sources, data classes, retention, provider exposure, and prohibited uses for the engagement.
Identify accountable reviewers, intervention points, escalation paths, and decisions that must remain human-led.
Test utility, quality, safety, and failure modes against examples and thresholds specific to the use case.
Align identities, roles, permissions, environments, and privileged actions with client policy and system design.
Make relevant inputs, sources, versions, outputs, changes, and decisions inspectable at an agreed level.
Information classes, system boundaries, policies, stakeholders, risks, and obligations.
Threats, permissions, data flows, oversight, evaluation, quality attributes, and control ownership.
Environment controls, code and configuration review, tests, release evidence, and exceptions.
Observability, support, incident paths, change control, evaluation, and knowledge transfer.
AI outputs may be inaccurate and require review before consequential use. Appropriate controls depend on the use case, data, users, model and tool behavior, client policy, and applicable obligations.
Cognelyra welcomes good-faith reports about a potential vulnerability in cognelyra.com or a public Cognelyra subdomain.
Email security@cognelyra.com with the affected URL, observed behavior, reproduction steps, potential impact, and a safe way to contact you. Do not include secrets or personal data in the initial message.
Limit testing to Cognelyra’s public website and data you own. Do not disrupt service, access or alter another person’s data, persist access, use social engineering, or test third-party systems. Stop and report promptly if you encounter sensitive data.
Cognelyra will review the report, may request clarification, and will coordinate disclosure when appropriate. Response and remediation timing depend on severity, reproducibility, affected providers, and available mitigations. No bounty is offered unless agreed in writing.
For a proposed engagement, Cognelyra can work through the client’s security, privacy, AI, legal, procurement, accessibility, and delivery requirements. Available evidence depends on the exact team, systems, providers, scope, and commercial terms.
Bring the use case, data boundary, consequence, and client requirements. We will help make the control system visible.
Start a conversation