Legal Pages

Security and Responsible Disclosure

Security practices, PCI statement, responsible disclosure, breach response, access controls, monitoring, and customer responsibilities.

Version 2026.06.07 | Effective June 7, 2026 | Last updated June 7, 2026

Security practices

  • HostKit uses reasonable safeguards including encryption in transit, role-based access, least privilege, monitoring, logging, backups, vendor controls, and incident response workflows.
  • Customers are responsible for strong passwords, account access, staff permissions, approved devices, lawful integrations, and prompt reporting of suspected compromise.
  • HostKit may restrict or suspend accounts, messages, integrations, or public pages to investigate abuse, spam, fraud, security risk, or legal risk.

Payments and PCI

  • HostKit uses Stripe-hosted or Stripe-processed payment workflows and does not store full card numbers or sensitive authentication data.
  • Customers handling payment data outside HostKit are responsible for their own PCI DSS obligations.
  • Payment security concerns should be reported promptly to security@hostkitapp.com.

Responsible disclosure and incidents

  • Security reports should include affected URL/account, reproduction steps, impact, screenshots or logs where safe, and reporter contact details.
  • HostKit aims to acknowledge credible security reports within 3 business days.
  • Do not access, modify, destroy, exfiltrate, publicly disclose, or disrupt data or systems while testing.
Questions: support@hostkitapp.comMailing address: HostKit Legal, North Carolina, United StatesRequest pricing