hm account

How this account is kept

The properties this surface is built to have, and how to tell us when one does not hold.

Reporting something

Write to security@hmcortex.com. A first reply comes within three working days. Report in good faith, do not use anyone else's account or data to demonstrate a problem, and we will not pursue you for it.

How sign-in works here

Reaching your account data

The pages that show your organisation and preferences are built on the server. The credential that reads them is minted for a single request and dropped when it ends: it is never placed in a page, never stored in your browser, and cannot be recovered from anything this surface sends you.

Between services, that credential is checked with public-key signatures against a published key set — the service that reads it holds nothing that could mint one.

What is not built yet