Security.
If you've found a security problem in something Considus makes, I'd like to hear about it, privately, and before anyone else does. Please don't open a public issue or a pull request for anything exploitable. Tell me what you found, how to reproduce it, and what it lets an attacker do.
This website
For a problem on considus.com, email security@considus.com and tell me which page it affects. That includes the code that runs on its server, such as the mailing-list sign-up and the support form. If email isn't an option for you, the support form reaches me too.
I'll acknowledge your report within 3 business days and keep you posted while I look into it.
This is coordinated disclosure, so please give me a reasonable amount of time to ship a fix before you make it public. You're welcome to the credit once it's out, or to stay anonymous, whichever you'd prefer.
The same address is in the site's security.txt, the file security tools look for.
What's out of scope
Services I don't control are out, because those aren't mine to fix. That means Cloudflare's own platform, which hosts the site, and EmailOctopus, which runs the mailing list.
The same goes for the reports an automated scan turns up: a missing security header, missing or weak SPF, DKIM and DMARC records, clickjacking on a page with nothing sensitive to click, and best-practice advice with no demonstrated impact. Social engineering and denial of service are out too.
Safe harbour
The site's terms ask you not to probe its security, and good-faith research under this policy is the exception. You won't face legal action from me or from Considus for research done in good faith, so long as you avoid violating anyone's privacy, avoid destroying data, and follow this policy.
Proton Bridge MCP and PageSpeed Insights MCP
I take reports for these two open-source servers through GitHub's private reporting. Open a private advisory on Proton Bridge MCP or on PageSpeed Insights MCP, and only you and I can see it, so we can sort it out there before it's public. If you'd rather not use GitHub, email security@considus.com instead.
A proof of concept helps, but a clear description is plenty. I'll confirm I've received it within a few days and keep you posted while it's being fixed, and once there's a fix out, you're welcome to the credit if you want it.
What counts as in scope is different for each, so it's spelt out in the Proton Bridge MCP policy and the PageSpeed Insights MCP policy. Bugs in Proton Mail Bridge itself belong with Proton, and the behaviour of Google's APIs is out of scope for PageSpeed Insights MCP.
Both have one line of development, on the main branch. Fixes land there, and there are no separately maintained older releases to back-port them to.
Catchlight
Catchlight publishes a policy with the code of each of its open-source repositories, in Catchlight-iOS, Catchlight-MacOS, Catchlight-Core and Catchlight-AppleStorage. Each one sets its own scope and says which versions get fixes.
Reports for any of them go to security@considus.com, the same address as this website, and those policies say how quickly I'll acknowledge a report and set out the safe harbour for research done in good faith.