Responsible disclosure

read

At Paranoid Secure Hosting, we consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.

If you discover a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. We would like to ask you to help us better protect our clients and our systems.

Please do the following:

What we promise:

scope:

The scope of this responsible disclosure applies to the following HTTP and HTTPS(rfc2616,rfc2817,rfc2818,rfc7540) services within the following matching addresses:
*.d9ping.nl. *.notefly.org. and *.postma.xyz.

We strive to resolve all problems as quickly as possible, and we would like to play an active role in the ultimate publication on the problem after it is resolved.

Reporting anonymously and full disclosure

If you want to report a security issues to us anonymously this is okay too Paranoid Secure Hosting will give credits to your nickname, if you want.
Also we won't punish you for doing full disclosure but doing responsible disclosure makes you eligible for a reward.
Futhermore Paranoid Secure Hosting would like to know where your full disclosure is published so Paranoid Secure Hosting can fix it ASAP.
Paranoid Secure Hosting believes that any disclosure is better than no disclosure.

1. We promise not to use, less than 9 characters(and too easy to guess) passwords for any account when password authentication is used.

Orginal text by Floor Terra, released under Creative Common 3.0 NL naamsvermelding

All security research that have been rewarded can be named on the hall of fame page.