What to send
- Include the affected URL, product surface, version, and environment.
- Provide clear reproduction steps and expected versus actual behavior.
- Attach timestamps, request identifiers, screenshots, or proof-of-concept material when relevant.
Security
Use this page to report vulnerabilities, find the canonical disclosure contact, and understand how Cosantoir routes security submissions. The published security.txt record remains the canonical machine-readable contact.
security-reports@cosantoir.com
Primary mailbox for vulnerability reports, coordinated disclosure, and urgent follow-up.
security@cosantoir.com
General security escalation channel for authenticated company security contact.
vulnerability@cosantoir.com
Technical disclosure path for reproducible findings and remediation coordination.
abuse@cosantoir.com
Use this mailbox for phishing, impersonation, abuse, or malicious use tied to the platform.
bugbounty@cosantoir.com
Researcher contact for scope, eligibility, and payout-program routing when a report qualifies.
/.well-known/security.txt
Use the machine-readable contact record published from the site root.
What to send
What happens next