1. In-Scope Systems
In-scope targets include the public VeltrixHost website, VeltrixHost-operated account interfaces and systems that VeltrixHost clearly controls. Customer-managed VPS, dedicated servers, websites and applications are not in scope without that customer’s explicit authorization.
2. Rules of Engagement
- Test only accounts and resources you own or are explicitly authorized to test.
- Do not access, copy, alter or delete another customer’s data.
- Do not perform DoS/DDoS, traffic flooding, brute-force attacks or resource-exhaustion testing.
- Do not use social engineering, phishing, physical intrusion or employee targeting.
- Stop testing once you have enough evidence to demonstrate a vulnerability safely.
- Keep the issue private until VeltrixHost has had a reasonable opportunity to investigate and remediate it.
Do not test customer websites, mailboxes, virtual machines or dedicated servers without the owner’s express authorization. Do not access or retain another person’s data, send phishing messages, test stolen credentials or interrupt services. If you encounter sensitive data unintentionally, stop testing and provide only the minimum evidence needed for a confidential report.
3. What to Include in a Report
- Affected URL, endpoint or system.
- Clear vulnerability description and likely impact.
- Minimal step-by-step reproduction instructions.
- Screenshots or sanitized request/response evidence where useful.
- Your preferred contact details, if you want follow-up.
4. Good-Faith Research
VeltrixHost will evaluate good-faith research reasonably when it follows this policy, avoids harm and is reported privately. This policy does not authorize activity that is independently unlawful or testing of systems not controlled by VeltrixHost.
5. No Guaranteed Bounty
VeltrixHost does not promise a paid bug bounty, reward or public recognition. Any reward or acknowledgement is discretionary and should not be assumed before testing.
6. Reporting Channel
Submit a vulnerability report through the VeltrixHost support system and clearly mark the ticket as a security or vulnerability report.
These website policies are intended to state VeltrixHost’s service rules clearly. Mandatory law may create rights or obligations that cannot be excluded by contract. If a requirement is important to your order, contact VeltrixHost before payment.
