CONSLE

Consle · Security Policy

Security.

Reporting a vulnerability

If you discover a security issue in Consle, email security@consle.com. Do not open a public issue.

Include:

  • A description of the issue
  • Steps to reproduce
  • The commit SHA or URL of the affected page
  • Your contact information

Receipt is acknowledged within 48 hours.

Scope

Consle Site is a static site with no user accounts, no forms that collect personal information, and no backend state. The primary security concerns are:

  • Supply chain integrity and dependency tampering
  • Content integrity and unauthorized changes to published copy
  • Privacy leaks from accidental inclusion of analytics or fingerprinting

Infrastructure

The marketing site is hosted on AWS S3 with CloudFront as the CDN. TLS is enforced on all connections. No cookies are set. No analytics that fingerprint visitors are deployed.

Platform security

The Consle product platform -- voter data, campaign finance, ad delivery -- operates under separate, stricter security policies. Platform security inquiries should be directed to security@consle.com.

Responsible disclosure

Consle does not operate a bug bounty program. Researchers who report valid issues are credited with permission.