Responsible Disclosure

If you find a security problem here, we want to hear about it — and we will not punish you for telling us.

How this site is secured

hostingflow.com is served over HTTPS with HSTS, a strict Content-Security-Policy and modern cross-origin isolation headers. There is no web contact form, no account system and no analytics running without your consent — so there is no user database to breach.

Reporting a vulnerability

Email [email protected] with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • the potential impact as you see it.

Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated, and credit you if you would like once it is resolved.

Please do not

  • Access, modify or delete data that is not yours, or degrade the service for others — no denial-of-service or spam testing.
  • Test domains or infrastructure belonging to the registries and registrars we write about. They are not ours.
  • Use social engineering or physical attacks.

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorised and will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].

A machine-readable version of this contact is published at /.well-known/security.txt.

Related: Privacy Policy · Contact