Skip to main content

Developer security

Make the boundary explicit

Security guidance is separated into controls implemented in this foundation, practices required of developers, future production capabilities, and formal claims that are not made.

Implemented in the foundation

Private-route noindex and sitemap exclusion, safe external-link helpers, explicit environment labels, and local-only Ask COGNI and sandbox boundaries.

Required developer practice

Protect credentials, use least-privilege scopes, separate environments, validate webhook signatures, and never send sensitive data to examples or analytics.

Planned production control

Identity provider integration, MFA, gateway enforcement, server-side metering, replay protection, alerting, and immutable audit storage.

Formal certification

No certification, accreditation, or compliance claim is made by this page.

Credential handling

  • Keep secrets out of source, logs, analytics, URLs, and screenshots.
  • Use separate sandbox and production credentials.
  • Rotate and revoke through an auditable, server-authoritative flow.
  • Use request and correlation IDs without exposing internal topology.

Request integrity

  • Validate callback and webhook URLs.
  • Use idempotency boundaries for duplicate submissions.
  • Verify webhook signatures and replay windows.
  • Redact credentials, request bodies, response bodies, and private tenant data.

Search CINTENT.tech

Search reviewed public content. Hosted search is not connected.

Voice is optional and requires explicit consent.
Enter a term to search reviewed public content.

Open full Search

Voice input is optional and requires explicit consent. Your browser may process audio using its own speech service. CINTENT.tech does not store raw audio; the transcript is placed in the editable question field and is not submitted automatically.