Responsible Disclosure

If you find a security problem here, we want to hear about it — and we will not punish you for telling us.

How this site is secured

sitedoc.net is served over HTTPS with HSTS, a strict Content-Security-Policy and modern cross-origin isolation headers. There is no web contact form and no account system, so there is no enquiry database to breach, and no third-party analytics run without your consent.

Reporting a vulnerability

Email [email protected] with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • the potential impact as you see it.

Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated, and credit you if you would like.

Please do not

  • Access, modify or delete data that is not yours, or degrade the service for others — no denial-of-service or spam testing.
  • Test domains belonging to our clients or to the parties in any dispute we handle.
  • Use social engineering or physical attacks.

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorised and will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].

A machine-readable version of this contact is published at /.well-known/security.txt.

Related: Privacy Policy · Contact