TRUST CENTER

How COSMO protects connected brand work.

A transparent view of COSMO’s security model, privacy practices, data-processing commitments and service status.

Last updated 25 August 2026

Security principles

  • Connected-provider credentials are handled on the server and are not intentionally exposed to the browser or Figma document.
  • Plugin access is tied to a COSMO user session and a specific device token that can be revoked.
  • Workspace data is separated through membership checks and database row-level access controls.
  • Billing webhooks are validated before plan state is changed.
  • COSMO avoids claiming certifications or assurance reports that have not been completed.

Current service providers and connected platforms

SupabaseAccount, database and application backendCore service
VercelApplication hosting and deliveryCore service
StripeSubscription billing when billing is enabledPayments
ResendTransactional email when configuredOptional service
KlaviyoCustomer-connected destination for email workflowsCustomer integration
FigmaDesign surface used by COSMO ConnectCustomer integration

Commercial legal readiness

These pages describe the product’s current technical and operational practices. Before COSMO accepts paid production customers, the public legal notice should also identify the final contracting operator, registered address and any jurisdiction-specific information required for launch. No placeholder legal identity is presented as fact.

Contact COSMO about procurement or privacy →