24/7/365 support support@nullstrata.space
Client login →

← Legal & policies

Security

How this storefront protects your data, and how to tell us about a vulnerability.

How we handle your data

  • No card data here. Payments happen on PayPal’s or the card processor’s own pages. This site never sees or stores card numbers.
  • No passwords here. Your control panel runs on a separate login system; this site has no customer accounts.
  • No stored order data. Checkout details go straight to our provisioning platform over an encrypted connection and are not kept on this server. Domain transfer (EPP) codes are never logged or stored.
  • Prices are set server-side. Plans, periods and prices are checked against the live catalogue; nothing in the browser can change what you pay.
  • Hardened by default. HTTPS everywhere with HSTS, a strict Content Security Policy, CSRF tokens on every form, secure host-only cookies and rate limits on search and checkout.
  • No third-party trackers. Statistics are cookieless and self-hosted. See Privacy.

Report a vulnerability

If you believe you’ve found a security issue on nullstrata.space, email security@nullstrata.space with the steps to reproduce it. We read every report and reply as fast as we can.

Please test only against your own orders and data, don’t access or change other people’s information, avoid anything that degrades the service (no load or denial-of-service testing), and give us reasonable time to fix the issue before sharing it publicly.

Issues in the control panel or the payment pages belong to those providers; send them to us anyway and we’ll pass them on.

Machine-readable contact: /.well-known/security.txt