What we store
Public records about domains: registration dates, nameservers, certificates, mail records, subdomains and the scripts your pages load. All of it is readable by anyone who asks the same questions we do.
Plus your email address and which domains you asked us to watch.
What we never have
- No credentials. We never ask for registrar, DNS, hosting or mail logins, and there is nowhere to enter them.
- No access to your systems. Nothing is installed and nothing connects inward.
- No card details. Payment is handled entirely by Paddle as Merchant of Record.
- No customer data beyond an email address.
This is the useful part. A service holding no credentials cannot leak credentials, and the answer to most security questionnaires is that the risk does not exist rather than that it is managed.
How the record is protected
Each stored snapshot carries a seal covering the previous one, so altering any historical entry breaks every seal after it. That makes tampering detectable rather than impossible — an important distinction, and the honest claim.
Backups run nightly, encrypted, to infrastructure separate from the server. Restores are tested quarterly, because an untested backup is a hope.
Reporting something
Write to security@domainledger.io. Include enough to reproduce it.
We will reply within two working days, tell you honestly whether it is a real problem, and fix genuine issues as quickly as we can. There is no bounty programme — this is a one-person business and pretending otherwise would waste your time.
Please do not test against other people's domains. Scanning is read-only against public records, so there is nothing to attack there, and doing so would affect businesses who did not ask.
What we would tell you if something went wrong
Which data was affected, when, and what we did. Within seventy-two hours of knowing. Including if the answer is embarrassing.