- Home
- Legal
- Vulnerability Disclosure Policy
Last updated: 10 October 2026
Introduction
hostavik welcomes reports from people who find a security weakness in our website or client area. This policy explains what is covered, how to look for weaknesses responsibly, and how to report what you find.
What Is Covered
This policy covers the hostavik website and client area on this domain.
It does not cover:
- websites, email or servers that belong to our customers, even when they are hosted with us;
- services run by other companies, such as payment providers and the suppliers of add-on products;
- attacks on our staff, offices or equipment, including social engineering and phishing.
Rules for Research
When you look for weaknesses, please:
- act in good faith and only use accounts that are your own;
- do not view, change, copy or delete other people's data. If you come across it, stop and tell us;
- do not disrupt the service, for example with denial-of-service tests or high-volume automated scanning;
- do not send spam or unsolicited messages to our customers or staff;
- do only as much as is needed to show that the weakness exists;
- give us a reasonable time to fix the problem before you tell anyone else about it.
How to Report
Send your report through our Contact Us page or, if you are a customer, in a support ticket. Please include:
- the page or address where you found the weakness;
- what the weakness is and what someone could do with it;
- the steps to reproduce it;
- how we can reach you if we have questions.
Please do not include other people's personal information in your report.
What Happens Next
We review the reports we receive and may contact you for more detail. This policy does not offer payment or other rewards for reports.
Changes to This Policy
We may update this policy at any time. Changes are posted on this page with a new date.
