CustomDomain™ operates public trust infrastructure (DNS automation and TLS issuance for customer domains), so we take reports seriously.
- Report a vulnerability: email security@customdomain.ai with details and reproduction steps. We acknowledge reports typically within 3 business days. The full security and responsible disclosure policy covers triage timelines, safe harbor, and coordinated disclosure.
- Scope: the customdomain.ai product and APIs, the hosted MCP server (mcp.customdomain.ai), the embeddable widget, and the repositories in this organization.
- Our posture: security practices, policies, sub-processors, and the compliance frameworks we track (SOC 2, ISO 27001, GDPR) are published on our Trust Center. We are not yet SOC 2 certified; the policy page states our current compliance status.
Please do not open public issues for security reports.