Cogway
Security
Last updated 2 August 2026
We take security seriously, even on a site as small as this one. If you find a vulnerability, we want to hear about it.
Reporting a vulnerability
Email [email protected] with the subject "Cogway security report". Please include enough detail to reproduce the issue: the URL, what you did, and what happened.
Please give us a reasonable chance to fix the issue before disclosing it publicly. We will acknowledge your report and keep you updated. There is no paid bounty, but genuine reports are credited if you would like.
Scope
Cogway is a static site. There is no backend, no database, no user accounts,
and no server-side code running on cogway.dev. The attack surface is mostly the
third-party services it loads (Google Tag Manager, which collects nothing until you consent, and
MailerLite for the newsletter, which loads only once you do) and the hosting and DNS in front of
it.
What is out of scope
- Issues in the third-party services themselves, which should be reported to them.
- Missing security headers that carry no practical exploit, though we still like to hear about them.
- Reports generated purely by automated scanners with no demonstrated impact.