generated: '2026-09-05' method: searched source: https://hackerone.com/cognizant note: >- Cognizant runs TWO distinct, independently verified disclosure channels — a corporate-wide HackerOne Vulnerability Disclosure Program, and a separate project-level security policy for the Cognizant AI Lab open-source repositories. Both are recorded because they route to different teams and an agent (or a researcher) needs to pick the right one. Verified with a control probe: hackerone.com/cognizant returned HTTP 200 with a real program profile photo and og:title "Cognizant - Vulnerability Disclosure Program | HackerOne", while a deliberately nonexistent handle (hackerone.com/cognizant-nonexistent-zzz9) returned 404 with no profile photo. The 200 is a live program, not a platform catch-all. programs: - name: Cognizant Vulnerability Disclosure Program type: vulnerability-disclosure-program platform: hackerone url: https://hackerone.com/cognizant scope: corporate bounty: false bounty_note: >- Listed by HackerOne as a Vulnerability Disclosure Program rather than a Bug Bounty Program. No award amounts were published on the public program page; recorded as no-bounty rather than assumed. evidence: url: https://hackerone.com/cognizant http_status: 200 og_title: 'Cognizant - Vulnerability Disclosure Program | HackerOne' control_probe: url: https://hackerone.com/cognizant-nonexistent-zzz9 http_status: 404 fetched: '2026-09-05' page_note: >- The program page is a JavaScript-rendered single-page app; program policy text and scope tables are not present in the served HTML. Presence and identity were established from the server-rendered OpenGraph metadata, not from the SPA body. - name: Cognizant AI Lab open-source security policy type: security-policy platform: github url: https://github.com/cognizant-ai-lab/neuro-san/blob/main/SECURITY.md scope: cognizant-ai-lab repositories (neuro-san and siblings) contact: labgithub@cognizant.com channel: email public_issues_prohibited: true acknowledgement_sla: 48 hours disclosure_model: coordinated — public disclosure after a fix is released supported_versions: latest: supported older: unsupported detail: >- The policy supports only the latest release and explicitly marks anything below it unsupported. This is also the closest thing the project publishes to a version support policy — see lifecycle/cognizant-technology-lifecycle.yml. evidence: url: https://raw.githubusercontent.com/cognizant-ai-lab/neuro-san/main/SECURITY.md http_status: 200 fetched: '2026-09-05' security_txt: served: false detail: >- /.well-known/security.txt returned 404 on both cognizant.com and www.cognizant.com. Neither disclosure channel above is discoverable from the domain root, which is the one gap worth reporting back to the provider: an RFC 9116 security.txt pointing at the HackerOne program would make an existing, working program machine-discoverable at zero cost.