generated: '2026-07-18' method: searched probe: false source: https://cognitohq.com/docs/guides/security description: >- Cognito publishes a security page with a responsible-disclosure contact and a PGP key for encrypted reports. No public bug-bounty program is active (the docs state they would like to be invited to a HackerOne program on request). policy: - https://cognitohq.com/docs/guides/security contact: - security@cognitohq.com pgp: key_type: RSA 4096-bit fingerprint: F6FCD28D156F39D7CD43F7E84FCDB8656AE77C43 bug_bounty: active: false notes: Docs indicate willingness to be invited to a HackerOne program on request. evidence: - source: https://cognitohq.com/docs/guides/security kind: security-page keywords: [security@, PGP, responsible disclosure]