How to report
Email security@consusindustries.co with:- A description of the vulnerability
- Steps to reproduce
- Impact assessment (what an attacker could do)
- Your contact information for follow-up
Scope
In scope: the API endpoint (api.consus.io), public-facing documentation, and
authentication and authorization mechanisms.
Out of scope: vulnerabilities in upstream AI model providers (AWS Bedrock, GCP
Vertex AI, Azure OpenAI), third-party libraries with an existing CVE, and social
engineering.
What we commit to
We will keep you informed as we investigate and resolve the issue.