Responsible disclosure
Plain-English version of our /security.txt commitment. If you find something wrong with webhost24.in, here is how to tell us - and what happens next.
How to report
- Email security@webhost24.in with a clear subject (e.g. "XSS on /apps/wordpress-hosting").
- If the report is sensitive, mark it CONFIDENTIAL in the subject line; we will reply on PGP.
- Include the URL, the steps to reproduce, and (where possible) a screenshot or video.
- We acknowledge every report within 1 business day.
What we promise
- Triage within 1 business day; first status update within 3 business days.
- Critical issues fixed within 7 days; high within 30 days; medium within 90 days.
- Credit in our security advisory (unless you ask to remain anonymous).
- No legal action against good-faith researchers; we follow the standard safe-harbor terms.
What we ask in return
- Give us a reasonable window before public disclosure (90 days from confirmation, or until we ship a fix - whichever is sooner).
- Avoid privacy violations, service disruption, and destruction of data during your testing.
- Don't exploit the vulnerability beyond what is necessary to demonstrate it.
- Don't social-engineer our staff or customers.