Local secrets. Narrow cloud data.
Conseqa is designed so provider credentials and executable verifier code stay in the customer-controlled runner.
Last updated 3 October 2026
Conseqa is operated by Devraj Jhala in India. For support, privacy requests, or security reports, contact jhaladevrajsinh11@gmail.com. These notices describe the current early-access service. They do not claim an independent legal review, regulatory certification, or a negotiated enterprise agreement.
Architecture boundary
The private runner stores provider credentials, executes read-only verification and continues scheduling while cloud connectivity is unavailable. The hosted control plane receives redacted lifecycle events, outcomes, trace metadata, manifests and JSON schemas.
Port 4319 is intended for a private application network only. Production documentation requires persistent SQLite, encrypted spool volumes, least-privilege provider credentials and read-only mounted contract packages.
Durability and integrity
Required actions are authorized only after the intent and exact contract hash are acknowledged by the runner or committed to the encrypted local spool. Artifacts use deterministic SHA-256 build hashes, and same-name/version packages with different hashes are rejected.
Implemented controls and limits
The implementation includes tenant row-level security policies, scoped environment API keys, deletion workflows, signed outbound webhooks, encrypted local spool storage and audit histories. These controls have not received an independent security audit. Conseqa does not claim SOC 2, ISO 27001, PCI DSS, HIPAA or any other certification.
Reporting
Report security findings to jhaladevrajsinh11@gmail.com. Include a minimal reproduction and affected version, not production secrets or other users’ data. Access testing must remain within systems and workspaces you own or have permission to test.