Security
Mail vulnerabilities to security@nulnet.com. Keep the testing to our own surface: no probing other tenants' VMs, no denial-of-service fire at the edge, no social engineering of staff.
The machine-readable policy lives at /.well-known/security.txt.
Verify us
Trust is checked, not requested. Three public artifacts let you audit our posture without writing to anyone:
- Warrant canary — a dated record that no warrants, gag orders or seizures have landed. A stalled update is the tell.
- Status log — incidents with dates, appended only when an incident happens.
- Looking glass — indicative RTT from every facility, so network claims are auditable.
Encrypted mail: ask for our PGP public key at security@nulnet.com and confirm the fingerprint over a second channel before use. Support tickets live in the client panel.