🔒 Security Policy
At HomeTending, we take security seriously. This page outlines our security practices and guidelines for reporting vulnerabilities responsibly.
Reporting Security Vulnerabilities
If you discover a security vulnerability in our website or services, please report it to us responsibly:
- Email:
[email protected]
- Please include details about the vulnerability and steps to reproduce it
- Do not publicly disclose the vulnerability until we have had time to address it
- Allow us 90 days to investigate and resolve the issue
Security Best Practices
- HTTPS Encryption: All communication with our site uses secure HTTPS encryption
- Data Protection: Customer data is never stored on our servers — form submissions are processed through Web3Forms
- No Passwords Stored: We do not require users to create accounts or store passwords
- Third-Party Security: We use trusted, security-audited third-party services for form handling
- Regular Updates: Site infrastructure and dependencies are kept current with security patches
Expected Response Timeline
- Initial Response: Within 2 business days of vulnerability report
- Investigation: We will investigate and develop a fix within 30 days
- Resolution: Once resolved, we may request you be credited in our acknowledgments (optional)
What We Will Not Accept
- Automated vulnerability scanning without permission
- Denial of service attacks
- Social engineering attempts
- Physical security testing without prior arrangement
Security.txt
Our security contact information is also available in our standard /.well-known/security.txt file for automated security tools.