Responsible Disclosure Policy

Scope

This policy applies to security vulnerabilities discovered in:

Hostphyl acts as the primary point of contact for all security-related matters concerning both our own sites and those of our managed clients. Because we design, build, and host sites for many organizations, we coordinate the entire disclosure and remediation process on behalf of affected clients where necessary.

Disclosure Guidelines

Rules of Engagement

For client websites, Hostphyl coordinates all testing activities with the respective clients. This means:

Security researchers must:

Explicitly Forbidden Actions

The following are strictly prohibited unless you have explicit written authorization from Hostphyl:

Generic or automated “header scans,” “low-risk best-practice findings,” or any submissions intended for marketing or lead generation will be disregarded.

Using this communication channel for any activities outside of vulnerability disclosure, including but not limited to: marketing and lead generation, will be ignored and your domain blocked.

Reporting Requirements

Your report should include:

Reports lacking reproducible detail may be closed as non-actionable.

Communication and Resolution Process

Initial Submission:

Send all reports to [email protected].

Assessment:

Reports are triaged and severity-rated within 72 hours based on impact, exploitability, and affected systems.

Remediation & Timelines:

SeverityTypical ResponseTarget Fix Window
Critical24 hoursWithin 7 days
High24 hoursWithin 14 days
Medium/Low72 hoursWithin 30 days

Hostphyl and affected clients may adjust these timelines depending on operational impact or complexity.

Verification:

Researchers may be invited to confirm fixes. Hostphyl ensures successful deployment before public disclosure or acknowledgment.

Status Updates:

Updates will be provided approximately every 72 hours until resolution or closure.

Public Disclosure:

Coordinated disclosure occurs only after the fix is deployed and (if applicable) the client has approved release details.

Compensation and Recognition

Legal Safe Harbor

Researchers who:

will receive:

We appreciate professionalism and integrity in all research activity.

Our Commitment

Hostphyl commits to:

Contact

To report a security issue or ask a question:

Email: [email protected]