CCOSIGNET

Security & trust

Security

Cosignet is a control for high-risk AI-agent actions, so we state plainly what we guarantee, what we store, and how to reach us. We describe cryptographic binding — not unbreakable security.

Who runs this: meet the founder.

Contact & responsible disclosure

Report a vulnerability to security@cosignet.com. Please include steps to reproduce and impact. We aim to acknowledge within a few business days. Test only against your own account and data; do not access other tenants' data, run denial-of-service, or spam real approvers. We will not pursue good-faith research that follows these rules.

Machine-readable policy: /.well-known/security.txt.

Approval integrity

Fail-closed by default

No signature, no approval. If the human does not approve, the request expires and your integration receives a non-approved decision (pending, rejected, or expired) — never approved. Your code should proceed only on an explicit approved status, so a timeout or outage fails safe.

Read Availability and failure modes, or check live status at status.cosignet.com.

Data handling

Approval link privacy

Approval links are private by default. Anyone who opens the link sees only that an approval is being requested — the action label and payload stay hidden until the approver proves who they are.

Link privacy is separate from the public transparency reveal below: link mode controls who can read a live request; public reveal permanently publishes an approved action into the append-only log.

Audit trail & retention

Each confirmation keeps its action, payload, hash, status, and (once approved) the raw assertion, viewable in the dashboard. We do not yet run automatic deletion; data is retained until you request removal. For deletion, export, or data-residency questions, contact security@cosignet.com. Configurable retention and regional storage are on the roadmap for Enterprise.

Public transparency log

Approvals are recorded in an append-only transparency log, in the spirit of Certificate Transparency. Each approval is a tamper-evident leaf in a Merkle tree, and we publish a signed tree head. Anyone can request an inclusion proof that a specific approval is committed under a published root — the audit trail is verifiable independently, not just on our say-so. Verify an approval →

Infrastructure & sub-processors

We run on a small, audited set of providers:

Full data-processing details, legal bases, and your data-subject rights are in the Privacy Policy.

Compliance status

Cosignet is in early access. We are not yet SOC 2 or ISO 27001 certified, and we don't claim to be — we'd rather state the posture plainly. Formal certification and contractual SLAs are on the roadmap for Enterprise. For a security review or questionnaire today, contact security@cosignet.com.

Put a signed approval in front of your riskiest actions

Free to start — no credit card.