# Security | VPSbit

> How to disclose VPSbit infrastructure vulnerabilities responsibly. No ID at signup. Crypto-only billing. 12 elite datacenters. ECC memory, NVMe disks. DDoS.

Source: https://vpsbit.io/security/

# Security

Mail vulnerabilities to security@vpsbit.io. Keep the testing to our own surface: no probing other tenants' VMs, no denial-of-service fire at the edge, no social engineering of staff.

The machine-readable policy lives at [/.well-known/security.txt](https://vpsbit.io/.well-known/security.txt).

## Verify us

Trust is checked, not requested. Three public artifacts let you audit our posture without writing to anyone:

- [Warrant canary](https://vpsbit.io/warrant-canary/) — a dated record that no warrants, gag orders or seizures have landed. A stalled update is the tell.

- [Status log](https://vpsbit.io/status/) — incidents with dates, appended only when an incident happens.

- [Looking glass](https://vpsbit.io/looking-glass/) — indicative RTT from every facility, so network claims are auditable.

Encrypted mail: ask for our PGP public key at security@vpsbit.io and confirm the fingerprint over a second channel before use. Support tickets live in the [client panel](https://vpsbit.io/panel/).
