Reporting a vulnerability
Email security@consentcook.com with enough detail to reproduce the issue — the affected address, the steps, and what you were able to do. If you would rather encrypt the report, say so and we will arrange it. Please report before disclosing publicly, and give us a reasonable opportunity to fix the issue first.
What we will do
We will acknowledge your report within two business days, tell you whether we have reproduced it within ten business days, and keep you informed while we fix it. We will tell you when the fix is live, and we are glad to credit you publicly if you would like that.
What we ask
Please test only against accounts and sites you own. Do not access, modify or retain other people's data, do not degrade the service for other users, and do not run automated scanning that generates significant load. If you accidentally reach data that is not yours, stop, and tell us what happened.
Scope
consentcook.com, the ConsentCook dashboard and API, the consent banner and loader we serve to customer sites, and our WordPress and Shopify applications. Out of scope: reports generated solely by automated scanners with no demonstrated impact, missing security headers with no exploitable consequence, social engineering of our staff or customers, and physical attacks.
Safe harbour
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat your report as an authorised contribution to the security of the service. If a third party brings action against you for work that followed this policy, we will make that authorisation clear.
Contact
security@consentcook.com. A machine-readable version of this policy is published at /.well-known/security.txt.