Last updated: October 8, 2026
These policies supplement the Terms of Service and Privacy Policy. Where applicable law requires otherwise, applicable law controls.
Security approach
SantosHosting operates and maintains its hosting environment, including the Calagopus management panel, supporting infrastructure, and applicable system updates. We use technical and administrative measures intended to reduce risk, but cannot guarantee that any internet-connected service is free of vulnerabilities or interruptions.
Customer responsibilities
You must maintain account security, protect credentials and API keys, keep your own workloads patched, restrict access to trusted users, and maintain independent backups. Do not use hosted resources to attack other systems or customers.
Report a vulnerability
If you discover a potential issue in SantosHosting-owned websites, client systems, or hosting infrastructure, contact [email protected] or submit a private ticket through the Client Area. Include affected endpoints, reproduction steps, observed impact, and minimal evidence required to investigate. Do not include credentials or unnecessary personal data.
Responsible testing
No public authorization to conduct penetration testing is granted by this policy. Avoid disruption, accessing other people's information, privilege escalation, persistence, automated scanning, or extracting data. Request written permission before active testing. Stop immediately if you encounter sensitive information or operational instability.
Coordination
We will review reports and may request clarification or coordinate disclosure. We do not operate a public bug bounty program or promise payment, legal immunity, or a fixed response timeline.
