Security Policy & Disclosure
Last Updated: September 2026 • NetPriot, LLC
1. Architecture & Infrastructure Hardening
NetPriot, LLC operates its web platforms using 100% static edge architecture (Cloudflare Pages), completely eliminating runtime application servers, database injection surfaces, and server-side session vulnerabilities.
All public endpoints enforce strict Content Security Policies (CSP), HSTS preload configurations (31536000 seconds), nosniff headers, frame isolation, and zero third-party tracking scripts.
2. RFC 9116 Responsible Disclosure
We welcome vulnerability reports from independent security researchers, customers, and partners.
Our formal disclosure guidelines are published at /.well-known/security.txt in adherence to RFC 9116.
To report a security finding, email contact@netpriot.com with detailed reproduction steps, potential impact analysis, and proof-of-concept material.
3. Safe Harbor Commitment
We consider research conducted under this policy to be authorized, constructive, and lawful.
We will not initiate legal action against researchers who make a good-faith effort to avoid privacy violations, data destruction, and service disruption, and who provide reasonable time to remediate issues before public disclosure.
4. Out-of-Scope Research
Denial of Service (DoS/DDoS) attacks against any NetPriot domain or edge routing layer.
Social engineering (phishing, vishing) targeting NetPriot employees, contractors, or marketplace customers.
Physical attacks against any facilities, fulfillment centers, or hardware infrastructure.
Automated rate-limiting spam or non-exploitable scanner reports.