Security
Where your code runs, where we stand on compliance, and how to report a vulnerability
Where your code runs
Cofibrant runs as a build step inside your own CI/CD pipeline. It is not a hosted service, and your code is never uploaded to us to be analysed.
- Runs in your pipeline
- The toolchain executes on your build machines, alongside the compiler you already use. Your source and binaries stay where they are.
- Nothing leaves your environment
- No source, no binaries, no build artefacts and no telemetry are transmitted to Cofibrant. There is no phone-home.
- Nothing for us to hold
- Because we operate no service that receives your code, there is no copy of it on our side to be exposed if we were breached.
Compliance
We do not hold a SOC 2 report today. A Type I audit is underway and we expect the report in September 2026; we will publish it here when it is issued, and begin the Type II observation window from that point.
If you need to complete a vendor security review before then, contact us and we will work through your questionnaire directly rather than ask you to wait.
Reporting a vulnerability
We build tools that rule out code execution in memory-unsafe binaries, so we hold our own surface to the same standard. If you have found a vulnerability, report it to us directly and we will work it with you.
- Report privately
- Use the form below or email us directly. Please don't open a public issue or post details anywhere first.
- Include enough to reproduce
- The affected component, what an attacker gains, and the steps that get us to the same result.
- Give us time to fix
- Hold off on public disclosure until a patch is out. We'll tell you when it ships and we're happy to coordinate timing.
- Expect a reply
- We acknowledge every report within 48 hours and keep you updated while we work it.
Scope. In scope: this website and any other service we operate. Out of scope: scanner output with no demonstrated impact, missing hardening headers with no exploit path, and denial of service. Please don't run automated scans against production or access data that isn't yours.
All reports are treated confidentially.
Prefer email? fin@cofibrant.ai ยท Machine-readable contact: /.well-known/security.txt