Operated by Hostin Technologies · contact@h0sint.com
h0SINT is hosted in the EU. Our infrastructure runs on self-managed Scaleway dedicated hardware in the Netherlands (EU), with full-disk encryption and access restricted to a private network. Traffic reaches it through Cloudflare's edge, which terminates TLS. We do not use US hyperscalers for primary data storage.
We build a picture of your company's external attack surface the way an outside attacker sees it — domains, subdomains, exposed services, certificates, leaked-credential mentions, and technology fingerprints — entirely from publicly available sources.
Our free scan tool lets you check the public attack surface of any domain, including ones you don't own — the same class of lookup any browser, search engine, or commercial attack-surface tool already performs. Please only scan domains you own or are authorised to assess. Reports are private by default: each one is reachable only via an unguessable link, and is never indexed by search engines. See our Privacy Notice for exactly what's collected and how it's retained and erased.
Your scan and report are private to you by default. A shareable report link is only created if you choose to generate one, and that link is never listed or searchable.
| Sub-processor | Purpose | Data processed | Location | Safeguard |
|---|---|---|---|---|
| Scaleway SAS / Online SAS | Application hosting — self-managed dedicated server (not a managed service) | Scan data, reports, application state | EU (Netherlands) | Full-disk encryption; private-network-gated access; no public SSH |
| Google LLC | Authentication (OAuth), lead-list backup, analytics (page views only) | Email, display name, profile picture URL (OAuth); anonymized page views | US | Standard Contractual Clauses; IP-anonymized analytics, no ad features |
| Cloudflare, Inc. | Edge network, DNS, WAF and TLS termination; all traffic to the app is proxied over Cloudflare Tunnel | Request metadata (IP, URL, user-agent) in transit; anonymous access logs, no long-term retention | US / global anycast (EU edge locations serve EU visitors) | Standard Contractual Clauses; no origin data at rest with Cloudflare |
| AI provider (configurable per deployment) | AI-assisted analysis of scan findings, cloud mode only | Scan/finding content, only if cloud mode is explicitly selected; local mode never leaves the host | Varies by provider | Local-only mode available for sensitive engagements; no silent cloud fallback once local-pinned |
The free passive scan performs no AI analysis at all — it runs a fixed set of public-source lookups and grades them, so no scan content from it reaches any AI provider.
A DPA is available on request for any customer whose engagement requires one signed before use — contact us at contact@h0sint.com.
We do not currently hold ISO 27001, SOC 2, or any other third-party security certification. We follow information-security practices aligned with ISO/IEC 27001:2022 (documentation available on request) and are targeting formal certification as we scale. We are not currently ISO 27001 certified.
security@h0sint.com — we acknowledge good-faith reports and will keep you updated until the issue is resolved.