Trust & Security

What we see, and what we never touch.

Operated by Hostin Technologies · contact@h0sint.com

Where your data lives

h0SINT is hosted in the EU. Our infrastructure runs on self-managed Scaleway dedicated hardware in the Netherlands (EU), with full-disk encryption and access restricted to a private network. Traffic reaches it through Cloudflare's edge, which terminates TLS. We do not use US hyperscalers for primary data storage.

What we do

We build a picture of your company's external attack surface the way an outside attacker sees it — domains, subdomains, exposed services, certificates, leaked-credential mentions, and technology fingerprints — entirely from publicly available sources.

What we don't do

Scanning a domain you don't own

Our free scan tool lets you check the public attack surface of any domain, including ones you don't own — the same class of lookup any browser, search engine, or commercial attack-surface tool already performs. Please only scan domains you own or are authorised to assess. Reports are private by default: each one is reachable only via an unguessable link, and is never indexed by search engines. See our Privacy Notice for exactly what's collected and how it's retained and erased.

Who can see your report

Your scan and report are private to you by default. A shareable report link is only created if you choose to generate one, and that link is never listed or searchable.

Sub-processors

Sub-processorPurposeData processedLocationSafeguard
Scaleway SAS / Online SASApplication hosting — self-managed dedicated server (not a managed service)Scan data, reports, application stateEU (Netherlands)Full-disk encryption; private-network-gated access; no public SSH
Google LLCAuthentication (OAuth), lead-list backup, analytics (page views only)Email, display name, profile picture URL (OAuth); anonymized page viewsUSStandard Contractual Clauses; IP-anonymized analytics, no ad features
Cloudflare, Inc.Edge network, DNS, WAF and TLS termination; all traffic to the app is proxied over Cloudflare TunnelRequest metadata (IP, URL, user-agent) in transit; anonymous access logs, no long-term retentionUS / global anycast (EU edge locations serve EU visitors)Standard Contractual Clauses; no origin data at rest with Cloudflare
AI provider (configurable per deployment)AI-assisted analysis of scan findings, cloud mode onlyScan/finding content, only if cloud mode is explicitly selected; local mode never leaves the hostVaries by providerLocal-only mode available for sensitive engagements; no silent cloud fallback once local-pinned

The free passive scan performs no AI analysis at all — it runs a fixed set of public-source lookups and grades them, so no scan content from it reaches any AI provider.

Data Processing Agreement

A DPA is available on request for any customer whose engagement requires one signed before use — contact us at contact@h0sint.com.

Certifications

We do not currently hold ISO 27001, SOC 2, or any other third-party security certification. We follow information-security practices aligned with ISO/IEC 27001:2022 (documentation available on request) and are targeting formal certification as we scale. We are not currently ISO 27001 certified.

Report a security issue

security@h0sint.com — we acknowledge good-faith reports and will keep you updated until the issue is resolved.

Contact

contact@h0sint.com