> ## Documentation Index
> Fetch the complete documentation index at: https://gateway.consus.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Report a Vulnerability

> How to responsibly disclose security vulnerabilities in the Consus Gateway

Consus Industries welcomes responsible disclosure of security vulnerabilities in the
Consus Gateway. If you've found something, we want to hear from you.

## How to report

Email **[security@consusindustries.co](mailto:security@consusindustries.co)** with:

* A description of the vulnerability
* Steps to reproduce
* Impact assessment (what an attacker could do)
* Your contact information for follow-up

Do not include sensitive data (API keys, customer information) in your report. If you
need to share sensitive details, request our PGP key.

## Scope

**In scope:** the API endpoint (`api.consus.io`), public-facing documentation, and
authentication and authorization mechanisms.

**Out of scope:** vulnerabilities in upstream AI model providers (AWS Bedrock, GCP
Vertex AI, Azure OpenAI), third-party libraries with an existing CVE, and social
engineering.

## What we commit to

| Step                                           | Timeline                |
| ---------------------------------------------- | ----------------------- |
| Acknowledge receipt                            | Within 2 business days  |
| Initial assessment and severity classification | Within 5 business days  |
| Status update to reporter                      | Within 10 business days |
| Remediation (critical/high)                    | Within 30 days          |
| Remediation (medium/low)                       | Within 90 days          |

We will keep you informed as we investigate and resolve the issue.

## Safe harbor

We will not pursue legal action against researchers who act in good faith and follow
this policy, avoid accessing or modifying other users' data, do not disrupt service
availability, and report findings promptly — allowing reasonable time for remediation
before public disclosure.

## Recognition

With your permission, we will credit you in our security advisories. We do not
currently offer a paid bug bounty program.
