# Compliance

What domainsearch24.eu actually runs on, kept honest and short. The
service is operated by botBrains GmbH, Berlin (see the
[imprint](/legal/imprint)).

<TableOfContents depth="2" />

## Server location

All servers are operated by Hetzner Online GmbH in ISO 27001-certified
data centers in Germany and Finland (EU). No data leaves the EU for
operation of the service.

## Subprocessors

One hosting provider; everything else the service consumes is public
data. See [subprocessors](/legal/subprocessors).

## Data retention

There are no accounts and no stored user profiles. Queried domain names
are processed in memory; availability caches (keyed by domain, not by you)
expire within 24 hours. Edge logs rotate within days. Rate-limit
counters are in-memory and decay within minutes. Browser bookmarks
("Saved") live only in your browser's localStorage: never on our
servers.

## Information security

Security posture matches the service's footprint: single-purpose Go
binary, loopback-only application listener behind a TLS-terminating
reverse proxy, systemd hardening (NoNewPrivileges, ProtectSystem=strict,
PrivateTmp), least-privilege service account, no inbound credentials or
secrets in the request path. The service itself is not ISO 27001
certified; the underlying Hetzner data centers are.

## Backups & disaster recovery

The service is stateless by design: no customer data exists to back up.
Recovery is redeployment from the versioned repository (single script),
plus warm-start caches that rebuild automatically from public sources.

## Logging & monitoring

Edge logs (timestamp, path, response code) for abuse defense and
debugging, rotated within days; systemd journal for service health. No
analytics or tracking of visitors.

## Vulnerability management

Dependencies are minimal and updated with each deploy; the OS is
Ubuntu LTS with unattended security updates. See the
[vulnerability disclosure policy](/legal/vulnerability-disclosure-policy)
for reporting.

## Incident response & breach notification

Incidents are handled by the operating team (see imprint). Since no
customer data is stored, breach exposure is limited to service
availability; material incidents affecting API consumers are announced
on this page and, for known API-key holders, by email without undue
delay and within 72 hours of confirmation.

## Personnel & confidentiality

The service is operated by botBrains GmbH staff under contractual
confidentiality obligations. Production access is limited to named
administrators using key-based SSH.

## Funding & stewardship

Funded by registrar referral commissions (disclosed on the landing
page) and operated as part of the botBrains GmbH service portfolio:
no venture funding, no data monetization.

## ESG: carbon footprint

Hetzner data centers run on 100% renewable energy (hydro/wind
certificates, per Hetzner's public statements). The service's design:
heavy caching, single small binary, no GPU workloads: keeps its
footprint minimal.

## Vulnerability disclosure policy

Please see [/legal/vulnerability-disclosure-policy](/legal/vulnerability-disclosure-policy).

## Penetration testing

No external penetration test has been commissioned yet for this
service. The attack surface is deliberately small (read-only API, no
authentication, no stored user data) and internal adversarial reviews
accompany feature work. Independent findings are welcome under the
disclosure policy.

## Certifications

The service itself holds no certifications. Hosting runs in Hetzner's
ISO 27001-certified data centers; the certificate is available from
Hetzner.

## Migration & data export

There is nothing to migrate: the service stores no account data. Saved
bookmarks live in your browser and can be exported from localStorage
(`ds-saved-v2`). API consumers can stop using the API at any time
without residual data on our side.

## Account deletion

There are no accounts. To have an API key revoked, email
[support@domainsearch24.eu](mailto:support@domainsearch24.eu).

## ISMS questionnaire

Due to capacity constraints we ask you do not send your own
questionnaire but use our normalized ISMS questionnaire at
[/legal/isms-faq.md](/legal/isms-faq.md). Please ask your AI of choice
to match your questions and flag if there is missing content, using
this prompt:

> "I need to fill out my companies isms security questionaire, it is
> attached. We'll be using domainsearch24 service. They provide answers
> to most questions at https://domainsearch24.eu/legal/isms-faq.md and
> https://domainsearch24.eu/legal/compliance.md. Please fill out my
> questionaire from that information. If one question cannot be
> answered, point it out to me later. Sometimes, reading
> https://domainsearch24.eu/docs can help resolve open questions not
> answered. Try to complete the full questionaire."

---

Last updated: August 2026.
