How we protect data
- Encryption in transit: this site accepts only HTTPS, with HSTS, and supports hybrid post-quantum key exchange (X25519MLKEM768) through our hosting provider.
- Encryption at rest: our providers encrypt all stored data.
- Least data: no analytics, trackers or third-party scripts. The waitlist stores only the details listed in the Privacy Notice.
- Strict browser policy: a Content Security Policy that allows scripts, fonts and connections only from our own domain, and blocks framing.
- Access control: production access is limited to the people who need it.
- Isolation: each customer's reports and uploads are stored separately under that account.
- Deletion: data is deleted on the schedule in the Privacy Notice and the DPA.
Our scanner
Shorward's scanner is deliberately gentle. For each host it makes a few standard TLS handshakes on port 443 to see which protocol versions and key exchange groups the server accepts, and reads the public certificate. It doesn't try to log in, send exploits, crawl pages or fuzz inputs.
- A one-off scan runs only when someone asks for a report on a domain.
- Continuous monitoring runs only on domains whose owner has added a DNS verification record.
- To stop scans of your domain, email [email protected]. We'll add it to our exclusion list.
Report a vulnerability
If you find a security issue in shorward.com or the Shorward service, email [email protected] with the subject "Security report". We'll acknowledge it within 2 business days and keep you updated until it's fixed.
We won't take legal action against good-faith research that:
- avoids privacy violations, data destruction and service disruption;
- only accesses data needed to show the issue;
- gives us reasonable time to fix it before public disclosure.
Out of scope: denial of service, social engineering, physical attacks, and reports from automated tools with no demonstrated impact. We don't run a paid bounty during the beta, but we're glad to credit you.
Machine-readable contact: /.well-known/security.txt