Consle · Security Policy
Security.
Reporting a vulnerability
If you discover a security issue in Consle, email security@consle.com. Do not open a public issue.
Include:
- A description of the issue
- Steps to reproduce
- The commit SHA or URL of the affected page
- Your contact information
Receipt is acknowledged within 48 hours.
Scope
Consle Site is a static site with no user accounts, no forms that collect personal information, and no backend state. The primary security concerns are:
- Supply chain integrity and dependency tampering
- Content integrity and unauthorized changes to published copy
- Privacy leaks from accidental inclusion of analytics or fingerprinting
Infrastructure
The marketing site is hosted on AWS S3 with CloudFront as the CDN. TLS is enforced on all connections. No cookies are set. No analytics that fingerprint visitors are deployed.
Platform security
The Consle product platform -- voter data, campaign finance, ad delivery -- operates under separate, stricter security policies. Platform security inquiries should be directed to security@consle.com.
Responsible disclosure
Consle does not operate a bug bounty program. Researchers who report valid issues are credited with permission.