Responsible Disclosure Policy
Applies to: host.yt, the customer panel, billing portal, support channels, and services provided by Marko Omelyash VARSOFIA.
Plain-language summary
This summary is for convenience only. The full provisions below form the legally relevant text.
1. Scope
This Policy applies to good-faith vulnerability reports concerning systems owned or operated by Hostyt.
2. Reporting
Send reports to [email protected] with a clear subject line such as “Security vulnerability report”. Include affected URL/IP/service, reproduction steps, impact, screenshots or proof of concept, and your contact details.
3. Rules for researchers
- Do not access, modify, delete, exfiltrate, or disclose customer data.
- Do not run destructive tests, spam, phishing, social engineering, DDoS, physical attacks, or persistence.
- Use only the minimum testing needed to verify the issue.
- Give us reasonable time to investigate and remediate before public disclosure.
- Stop testing immediately if you encounter personal data, secrets, or service disruption.
4. Our process
We aim to acknowledge reports, validate impact, prioritise remediation, and communicate status where possible. Timelines depend on severity, complexity, third-party involvement, and operational risk.
5. Safe harbour
We will not pursue legal action for good-faith research that complies with this Policy. This does not protect malicious activity, privacy violations, extortion, data theft, or actions against third-party systems.
6. Rewards
Unless a separate bug bounty programme is expressly published, reports are voluntary and no reward is guaranteed.
Updates
We may update this document from time to time. The version published on host.yt is the current version. If a change materially affects active paid services, we may notify affected customers by email, account notice, ticket, or another reasonable channel.