Cocoding legal

Security Overview

A public overview of Cocoding security responsibilities and reporting channels.

Effective 11 October 2026 · Last updated 11 October 2026

Shared responsibility

Cocoding is a development and operation platform, so security is shared. Cocoding protects the hosted service and provides platform controls. Customers remain responsible for their accounts, organization membership, connected providers, source and generated code, dependencies, secrets, data classification, deployment configuration, and review of output.

Platform approach

The platform is designed around authenticated access, scoped authorization, auditable administrative actions, workload isolation, controlled delivery, secret boundaries, and operational monitoring. Available controls and evidence can vary by plan, deployment stage, and written agreement.

Security documentation describes current behavior rather than promising that any system is invulnerable. Enterprise questionnaires, architecture details, or assurance materials may require an appropriate confidentiality process.

Customer practices

Customers should:

  • Use unique authentication, enable available multi-factor or enterprise identity controls, and review active sessions and organization membership.
  • Grant the least access needed to repositories, clouds, models, integrations, and service accounts, and rotate credentials after suspected exposure.
  • Keep secrets out of prompts, source control, screenshots, support messages, and generated artifacts unless an approved secret mechanism is intended for that data.
  • Review and test generated code, dependencies, infrastructure changes, and deployments before exposing them to users or sensitive data.
  • Maintain appropriate backups, incident procedures, and recovery plans for applications built or operated with Cocoding.

Report a vulnerability

Email security@cocoding.ai with the affected surface, reproducible steps, impact, and sanitized evidence. Do not include credentials, customer content, personal data, or destructive proof beyond what is necessary. Do not open a public issue for an unremediated vulnerability.

This page is not a bug-bounty promise, safe-harbor agreement, certification, service-level agreement, or warranty. Any such commitment must be stated in a separate written agreement.

Legal questions: legal@cocoding.ai