Security and Vulnerability Disclosure
A safe, coordinated route for reporting potential BlinkHost vulnerabilities.
Send potential BlinkHost security vulnerabilities to security@blinkhost.me. Include the affected asset, prerequisites, reproducible steps, impact, non-destructive proof and a safe contact method. Do not include secrets or personal data beyond what is necessary.
Research boundaries
Act in good faith. Test only BlinkHost-owned assets clearly in scope or accounts/resources you control. Stop if you encounter customer data. Do not exfiltrate data, access another tenant, degrade service, persist, socially engineer, spam, demand payment, publish before coordination, or use destructive testing. Denial-of-service, physical testing and third-party provider systems are out of scope unless we give written authorisation.
Our commitment
We will acknowledge a sufficiently detailed report, investigate, communicate material progress where feasible and coordinate disclosure timing based on risk and remediation. Good-faith research that follows this policy will not be treated as malicious under our Acceptable Use Policy. This is not a promise of reward or immunity from law and cannot authorise testing of third-party systems.
For an active incident or exposed credential, label the message urgent and revoke or rotate the credential immediately where you control it.