Device-bound access, encrypted credentials, workspace isolation and server-side integration handling.
02PrivacyWhat account, product and support data COSMO processes and why.
03Data ProcessingController/processor roles, customer instructions, subprocessors and deletion commitments.
04StatusA live snapshot of the COSMO web app, account services and integration gateway.
Security principles
- Connected-provider credentials are handled on the server and are not intentionally exposed to the browser or Figma document.
- Plugin access is tied to a COSMO user session and a specific device token that can be revoked.
- Workspace data is separated through membership checks and database row-level access controls.
- Billing webhooks are validated before plan state is changed.
- COSMO avoids claiming certifications or assurance reports that have not been completed.
Current service providers and connected platforms
Commercial legal readiness
These pages describe the product’s current technical and operational practices. Before COSMO accepts paid production customers, the public legal notice should also identify the final contracting operator, registered address and any jurisdiction-specific information required for launch. No placeholder legal identity is presented as fact.