# Security | NulNet

> How to disclose NulNet infrastructure vulnerabilities responsibly. No ID at signup. Crypto-only billing. 21 datacenters. ECC memory, NVMe disks. DDoS filtering.

Source: https://nulnet.com/security/

# Security

Mail vulnerabilities to security@nulnet.com. Keep the testing to our own surface: no probing other tenants' VMs, no denial-of-service fire at the edge, no social engineering of staff.

The machine-readable policy lives at [/.well-known/security.txt](https://nulnet.com/.well-known/security.txt).

## Verify us

Trust is checked, not requested. Three public artifacts let you audit our posture without writing to anyone:

- [Warrant canary](https://nulnet.com/warrant-canary/) — a dated record that no warrants, gag orders or seizures have landed. A stalled update is the tell.

- [Status log](https://nulnet.com/status/) — incidents with dates, appended only when an incident happens.

- [Looking glass](https://nulnet.com/looking-glass/) — indicative RTT from every facility, so network claims are auditable.

Encrypted mail: ask for our PGP public key at security@nulnet.com and confirm the fingerprint over a second channel before use. Support tickets live in the [client panel](https://nulnet.com/panel/).
