The one-pager for vendor reviews — last updated 2026-09-11
Architecture
Serving infrastructure is physically separated from data production. The public endpoint is fronted by
Cloudflare (TLS 1.3, DDoS protection) and connected via outbound-only tunnel — the serving host accepts no
inbound connections and exposes no ports. The analytical dataset served is a read-only weekly snapshot;
production systems are never reachable from the public surface.
Authentication & authorization
Access keys are stored as SHA-256 hashes only; shown once at issuance; revocable instantly.
OAuth 2.1 with PKCE for AI-assistant connectors; opaque server-side tokens, revocation cascades from the key.
Entitlements are checked server-side on every request — nothing trust-sensitive lives in tokens.
Data protection
Lawful public-source intelligence: the dataset is built entirely on open-source signals — DNS,
HTTP, TLS, public registry-scale data, and source-linked public M&A records. No private customer data,
no credentialed access, no leaked data, no intrusive scanning, and nothing appended from personal
contact or consumer-profile sources.
Answers are row-capped and rate-limited; the surface is designed for analysis, not extraction.
Customer query subjects are confidential: never visible to other customers, never sold; parameters
reduced to theme-level aggregates after 90 days.
Payment data is handled entirely by Polar, our merchant of record, with card payments
processed by Stripe for Polar - we never see card numbers.
Reporting a vulnerability
If you believe you've found a security issue in hostingbrain.ai or mcp.hostingbrain.ai, tell us at
hello@hostingbrain.ai — a founder reads it directly. We'll
acknowledge within 2 business days, keep you informed while we fix it, and credit you if you want credit.
Good-faith research against our own endpoints is welcome; please don't test with real customer data,
degrade the service, or access data that isn't yours. Machine-readable contact:
/.well-known/security.txt.
Honest scope
We are a small, pre-launch product and say so: no SOC 2 yet, no formal certifications. What you get
instead is a minimal attack surface (one endpoint, read-only data, no inbound network path), current
patching, and a founder who answers security questions directly at hello@hostingbrain.ai.