← Tool

Security Policy

This document describes the security practices, responsible disclosure process, and data handling policy for diag.md — a network diagnostic tool operated by iHost.md.

Last updated: March 2026

Responsible Disclosure

We take security seriously. If you discover a vulnerability in diag.md or any iHost.md service, we encourage responsible disclosure and will work with you to resolve it promptly.

Scope

The following assets are in scope for security research:

✓ diag.md ✓ ihost.md

The following are explicitly out of scope:

✗ Third-party services (proxycheck.io, Google Fonts) ✗ Social engineering attacks ✗ Physical security ✗ Denial of service attacks

Please do not perform automated scanning, fuzzing, or load testing against production systems without prior written permission.

Data Collected

diag.md collects the following data only when a user explicitly clicks "Generate Report":

No data is collected passively. Visiting the page without clicking "Generate Report" stores nothing server-side.

Data Storage & Retention

No Advertising or Tracking

Transport & Infrastructure Security

Contact

Security Contact

For security issues: security@ihost.md
For general support: support@ihost.md
Machine-readable: /.well-known/security.txt