01
Reporting a vulnerability
A public security reporting channel has not been announced yet.Do not post sensitive reports publicly. Reports should include the affected version, impact, reproduction steps, and sanitized evidence. Do not include passwords, API keys, access tokens, private keys, or user data.
02
Scope
This policy covers code maintained in the Con[s]ept repository. Provider CLIs, identity services, hosting platforms, repositories, devices, and networks are governed by their own security policies.
Test only systems and data you own or have explicit permission to test. Avoid denial of service, destructive actions, social engineering, and access beyond what is necessary to demonstrate the issue.
03
User responsibilities
- Keep Con[s]ept, provider CLIs, and operating systems current.
- Review agent commands and source changes before accepting them.
- Protect pairing links and revoke credentials after suspected exposure.
- Use isolated test state instead of a live Consept home directory.
- Grant providers and integrations only the access they need.
04
Updates
This policy will change as Con[s]ept gains new distribution and hosting surfaces. Any future hosted service must publish its own accurate privacy and service terms before launch.