Security & Responsible Disclosure

We engineer DNS security for a living, so this site is held to the same standard.

How we secure this site

dns.enterprises is served over HTTPS with HSTS, a strict Content-Security-Policy, and modern cross-origin isolation headers. There is no third-party advertising or tracking, no analytics running without consent, and no web contact form — so no enquiry data sits in a website database.

How we handle client data

DNS work means access to zone data, registrar accounts and sometimes production change control. Access is scoped to the engagement, changes are made through reviewable workflows rather than ad-hoc console edits, and data is retained only as long as the engagement requires. A data processing agreement is available as part of contracting. See our privacy policy for the detail.

Reporting a vulnerability

If you believe you have found a security vulnerability in this website, we want to hear from you. Email [email protected] with:

  • a description of the issue and where you found it;
  • the steps needed to reproduce it; and
  • the potential impact as you see it.

Please give us a reasonable chance to investigate and fix it before disclosing publicly. We will acknowledge your report, keep you updated, and credit you if you would like.

Please do not

  • Access, modify or delete data that is not yours, or degrade the service for others (no denial-of-service or spam testing).
  • Use social engineering or physical attacks against our people or infrastructure.
  • Run high-volume automated scans, or test DNS infrastructure belonging to our clients.

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorised and will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].

A machine-readable version of this contact is published at /.well-known/security.txt.

Related: Services · Privacy · Contact