02 Contact
One address for security reports.
Report
Send security reports to zfa@consensor.io, in English. Named clients report through the same address. To encrypt a report, use the OpenPGP key, fingerprint 8D77 EEF8 97FF 688C BCF0 8A3D 178F 52F4 FAC6 CB6E.
03 Scope
What this notice covers.
Scope
This host and the hostnames it is bound to. Every other hostname, the edge platform and volumetric denial of service are out of scope.
04 Position
Not a public assessment target.
Position
There is no public invite, no safe harbour and no bug-bounty programme. People will still try. That is expected and not invited. Unauthorised probing is monitored and treated as hostile.
This notice expires on 20 September 2027. The same content is served to machines as plain text at this address.