Security Policy
How we protect our infrastructure and how you can report security issues responsibly.
Security Commitment
PhishDestroy takes security seriously. We protect our infrastructure with industry-standard measures and welcome responsible disclosure from security researchers.
Infrastructure Security
We implement multiple layers of security to protect our systems and the data we handle:
- Transport encryption: All connections use TLS 1.2+ (HTTPS everywhere). HSTS is enforced with a one-year max-age including subdomains.
- CDN & DDoS Protection: We use Cloudflare as our CDN and DDoS mitigation layer. Cloudflare provides WAF (Web Application Firewall), rate limiting, and bot management.
- Access controls: Administrative access is restricted by role, protected with multi-factor authentication, and logged for audit.
- Content Security Policy: CSP headers restrict script execution sources, mitigating XSS and injection attacks.
- Security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and Permissions-Policy are set on all responses.
- Regular reviews: We conduct periodic security reviews of our codebase, dependencies, and infrastructure configuration.
- Input Sanitization: All threat reports are treated as untrusted. We use strict sandboxing and multi-stage sanitization to process malicious indicators.
Responsible Disclosure
If you discover a security vulnerability in our systems, please report it responsibly. For full details, see our Responsible Disclosure Policy.
Reporting a Vulnerability
To report a security issue, email us at abuse@phishdestroy.io. Please include:
- A detailed description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including URLs, payloads, or proof-of-concept code.
- Your preferred method of contact for follow-up.
For encrypted communication, use our PGP key at /.well-known/pgp-key.txt. Machine-readable info at /.well-known/security.txt.
Our Commitments to Researchers
When you report a security issue in good faith, we commit to:
- Acknowledge receipt within 48 hours.
- Investigate the issue promptly and keep you informed.
- Not pursue legal action against researchers acting in good faith. This does not extend to sanctioned jurisdictions or offensive operations.
- Credit you publicly if you wish (or maintain anonymity).
- Work with you on coordinated disclosure timelines.
Scope
This security policy applies to:
- The phishdestroy.io website and all subdomains.
- The Destroy API at api.destroy.tools.
- The Domain Analyzer at analyze.destroy.tools.
- Our Telegram bot (@PhishDestroy_bot).
- Our data processing and storage systems.
Out of scope: social engineering attacks against operators, physical security, denial-of-service testing, and issues in third-party services (GitHub, Telegram, Cloudflare).
Incident Response
- Identification: Detect and classify the incident.
- Containment: Isolate affected systems to prevent further damage.
- Eradication: Remove the threat and patch the vulnerability.
- Recovery: Restore services and verify integrity.
- Post-incident review: Document lessons learned and improve defenses.
Contact
- Email: abuse@phishdestroy.io
- PGP key: /.well-known/pgp-key.txt
- security.txt: /.well-known/security.txt