BorgohostSee pricing

Security and vulnerability disclosure

If you have found a security problem, we want to hear about it and we will not come after you for telling us.

Last reviewed 8 August 2026.

Reporting

Email security@borgohost.com. Include what you found, where, and enough detail to reproduce it. A proof of concept helps. Plain text in the email body is better than an attachment we might not be able to open.

Please do not open a public issue, post it publicly, or tell us on social media first.

What we promise you

AcknowledgementWithin 2 working days, by a human, not an autoresponder.
An assessmentWithin 10 working days: whether we agree it is a vulnerability, our severity view, and what we intend to do.
ProgressAn update at least every 14 days while it is open.
CreditNamed acknowledgement if you want it, anonymous if you prefer, and nothing published without asking you first.
HonestyIf we decide not to fix something, we tell you that and why, rather than leaving the report open forever.

Working days here mean 09:00 to 17:30 CET, Monday to Friday. There is one person behind this address.

Safe harbour

If you follow this policy in good faith, we will not pursue legal action against you, and we will not report you to law enforcement, for your research. If a third party brings a claim about research that complied with this policy, we will make it clear that you were authorised.

Good faith means: you stopped as soon as you confirmed the issue, you did not access, modify, exfiltrate or destroy anyone else's data, you did not degrade the service for anyone, and you gave us a reasonable chance to fix it before telling anyone else. 90 days is a reasonable chance; if we have not fixed it by then, publish, and please tell us you are about to.

In scope

  • borgohost.com and its subdomains.
  • The customer dashboard and the billing system, once they exist.
  • Our email authentication, and anything that lets someone send mail as us.
  • Our infrastructure, where you found it without attacking it.

Out of scope

  • Customer websites. They are our customers' property, not ours to authorise testing on. If you have found something in a site we host, report it and we will pass it on, but do not test further.
  • Anything requiring denial of service, load or stress testing, or brute force at volume.
  • Social engineering, phishing, or physical access attempts against any person.
  • Automated scanner output with no demonstrated impact. A scanner rating is not a finding.
  • Missing headers, cookie flags or TLS configuration preferences with no exploitable consequence.
  • Vulnerabilities in third-party software with no exploitable path in our configuration. Tell the vendor.
  • Reports about the absence of a certification. See below.

No bug bounty, and no certifications

There is no money. We will not pay a bounty and we would rather say so at the top than have you invest a week and then ask. Reports are read carefully and acted on regardless.

Borgohost holds no SOC 2, ISO 27001 or PCI DSS certification and does not claim otherwise anywhere. Card details are handled entirely by our payment provider and never reach our servers, which keeps that exposure to a minimum, but a minimum is not a certification. No independent penetration test has been carried out yet; when one has, this page will say so and give the date.

Our own security

The measures are in Annex II of the Data Processing Agreement, split into what isrunning today and what is committed before the first customer site exists, followed by what is missing outright. Three lists rather than one, because a security annex that reads as a single set of present-tense facts is the version most likely to be quietly wrong.

If we have a breach

We tell affected customers without undue delay and within 24 hours of becoming aware, with what we know, what we do not yet know, and what we are doing. We will not wait until the picture is complete before telling you something happened. Details in clause 6 of the DPA and the Privacy Policy.