Security

Last updated 2026-06-12 · the architecture, controls, and posture for cogos.5ceos.com

This page consolidates the security claims the landing page makes into one document procurement teams can read in a single sitting. Each item is tagged honestly: shipped means the runtime enforces it today and it's customer-verifiable; partial means it's enforced for the listed scope but has named exclusions; roadmap means committed-direction but not yet shipping.

Data at rest shipped

Data in flight shipped

Per-response cryptographic receipts shipped

Every /v1/* response carries two independent receipts that bind the response to the running build and the audit chain head:

Image supply chain shipped

Customer authentication shipped

Runtime hardening shipped

Key management partial

Compliance roadmap roadmap

The following are committed-direction, not shipping:

Responsible disclosure

Found a security issue? Email support@5ceos.com with the subject line "Security Disclosure". Include reproduction steps and an estimate of the affected tenants. We acknowledge within 1 business day, triage within 3 business days, and we'll keep you informed through the fix. We do not currently run a paid bug-bounty program; we publicly credit researchers in /trust advisories after the fix ships, with the researcher's permission.