Vulnerability disclosure policy#
We welcome good-faith security research into domainsearch24.eu.
Scope#
- domainsearch24.eu and domainsearch24.com (web UI and API)
- The published API under
/api/v1
Out of scope: denial-of-service testing, automated scanning at volumes that degrade the service, social engineering, physical attacks, and third-party services we do not operate (registrars, registries, DNS resolvers, Hetzner).
How to report#
Email security@domainsearch24.eu with a description, steps to reproduce, and impact. You will receive an acknowledgment within 3 business days and a substantive assessment within 10 business days.
Our commitments#
- We will not pursue legal action for good-faith research that respects this policy, avoids privacy violations and service disruption, and gives us reasonable time to remediate before public disclosure.
- We aim to remediate confirmed vulnerabilities within 90 days and will credit you (if desired) once fixed.
Your commitments#
- Do not access, modify, or delete data that is not yours (the service stores none, but logs and caches exist).
- Report promptly; do not exploit beyond what is needed to demonstrate the issue.
Last updated: August 2026.