Security Policy
Last updated: August 2026
Tidy Names holds registrar credentials and domain portfolios on behalf of its customers, so we take reports about this service seriously. If you believe you have found a vulnerability, we want to hear from you.
Reporting a Vulnerability
Email vulnerability@tidynames.com with:
What you found. A description of the issue and where in the service it appears.
How to reproduce it. The steps, requests, or payloads needed to see the behaviour again.
Why it matters. What an attacker could actually do with it.
Please give us a reasonable chance to fix the issue before disclosing it publicly. A machine-readable version of this policy is published at /.well-known/security.txt, per RFC 9116.
What to Expect
We are a small team, not a 24/7 security operation, so these are honest targets rather than contractual commitments:
Acknowledgement. Within 2 business days of your report.
Initial assessment. Within 5 business days.
Resolution timeline. Communicated within 10 business days, then prioritised by severity.
We are grateful for reports, and will happily credit you once an issue is resolved if you would like us to.
Scope
In scope. The Tidy Names website, the dashboard, and the API - for example cross-site scripting, injection, authentication or authorisation flaws, tenant isolation failures that expose another organisation's domains, exposure of stored registrar credentials, server-side request forgery, and sensitive-data exposure.
Out of scope. Please do not report these, and please do not test them against the live service:
Volumetric denial-of-service or traffic-flooding attacks.
Automated scanner output with no demonstrated, exploitable impact.
Missing security headers or best-practice suggestions with no concrete attack.
Spam or abuse of the contact and sign-up forms themselves - rate limiting and bot protection are known, deliberate trade-offs.
Social engineering of the team or its providers, and physical attacks.
Vulnerabilities in upstream dependencies that already have a public CVE - please report those to the upstream maintainer.
Weaknesses in a registrar, DNS host, or other third-party provider we integrate with. Please report those to the provider directly. If the weakness is in how we use their API, that is in scope and we want to hear about it.
Findings about domains you monitor with Tidy Names - a missing DMARC record on your own domain, for example - are product output, not vulnerabilities in the service. The Email Security guide covers those.
Safe Harbour
We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy: who avoids privacy violations and service disruption, only interacts with accounts, domains, or data they own or have permission to test, and gives us a reasonable time to respond before any public disclosure.
Testing against another customer's account or domains is never in good faith. If you are unsure whether an action is acceptable, ask us first at the address above.
Contact
For any security question, email vulnerability@tidynames.com. For anything else, use the contact form. Our security practices as a whole are described on the Trust page.