Intent™ Logo
Intent™ — A Non-Profit | Free Subdomains

Security Policy

Information about how Intent™ FreeDomain approaches security, vulnerability reports, responsible disclosure, and protection of our services and users.

Security matters to Intent.

We work to protect our infrastructure, DNS services, accounts, and users from unauthorized access, abuse, and security threats. If you discover a security vulnerability, please report it responsibly.

1. Security Principles

Intent aims to maintain reasonable technical and organizational safeguards designed to protect the availability, integrity, and confidentiality of information and services under our control.

Security is an ongoing process. We continuously review our infrastructure and procedures as our services evolve.

2. Infrastructure Security

Intent uses technical controls and operational practices intended to protect its infrastructure and services. Depending on the service and infrastructure involved, these may include:

  • Access controls and authentication mechanisms
  • Network and infrastructure monitoring
  • Logging and security event analysis
  • Service isolation and access restrictions
  • Software and infrastructure updates
  • Backup and recovery procedures where applicable
  • Abuse detection and prevention mechanisms

3. Account Security

Users are responsible for maintaining the security of their Intent accounts and credentials.

  • Keep passwords and authentication credentials private.
  • Do not share account credentials with unauthorized individuals.
  • Use a strong, unique password for your account.
  • Contact Intent if you believe your account has been compromised.

Intent may temporarily restrict an account when there is reasonable evidence of unauthorized access, compromise, or malicious activity.

4. DNS and Domain Security

DNS records and subdomains are an important part of the Intent service. We may investigate or restrict DNS configurations that appear to be involved in security abuse, phishing, malware distribution, fraud, or other prohibited activity.

Users are responsible for ensuring that destinations configured through their subdomains are legitimate and comply with our policies.

5. Security Monitoring

Intent may collect and analyze security-related information necessary to protect its services and investigate suspected abuse.

This may include information such as IP addresses, timestamps, user agents, account activity, DNS activity, and relevant security events, subject to our Privacy Policy .

6. Vulnerability Reporting

If you discover a potential security vulnerability affecting Intent services, please report it to us as soon as reasonably possible.

Security reports are most useful when they include enough information for our team to understand and reproduce the issue.

Security reports:

Email: contact@int.yt

7. Responsible Disclosure

We encourage responsible security research that helps improve the security of Intent services.

When investigating a potential vulnerability, security researchers should make reasonable efforts to avoid accessing, modifying, deleting, or exposing information belonging to other users.

Researchers should also avoid actions that could negatively affect the availability or performance of Intent services.

8. Security Testing

Security testing must be performed responsibly and without disrupting Intent services or accessing data that does not belong to the researcher.

The following activities are not considered acceptable security testing without explicit authorization:

  • Denial-of-service or distributed denial-of-service testing
  • Large-scale automated scanning that could affect service availability
  • Accessing or modifying another user's data
  • Destructive testing
  • Social engineering against Intent staff or users
  • Attempting to compromise third-party systems through Intent infrastructure

9. Security Incidents

If Intent identifies a security incident that may affect its services or users, we may take measures necessary to contain, investigate, and remediate the incident.

Depending on the circumstances, this may include:

  • Restricting affected accounts or services
  • Rotating credentials or security keys
  • Blocking malicious traffic or activity
  • Removing compromised resources
  • Preserving relevant security logs
  • Working with infrastructure providers and other appropriate parties

10. Third-Party Services

Intent may rely on third-party infrastructure, hosting providers, registrars, DNS providers, security services, and other technology providers.

The security practices of those providers may affect services provided through Intent. Third-party services remain subject to their own policies and security practices.

11. Abuse and Security Cooperation

Intent may cooperate with infrastructure providers, registrars, security organizations, law-enforcement agencies, and other authorized parties when reasonably necessary to investigate or mitigate security incidents, abuse, fraud, or other unlawful activity.

Any disclosure of information is handled in accordance with applicable requirements and our Privacy Policy .

12. No Guarantee of Absolute Security

While Intent takes reasonable measures to protect its services, no online service or infrastructure can be guaranteed to be completely secure.

Users should maintain appropriate security practices for their own accounts, applications, websites, and infrastructure.

13. Changes to This Policy

Intent may update this Security Policy as our services, infrastructure, security practices, or requirements change.

The latest version published on this page will represent the current Security Policy.

Contact Us

Security concerns and vulnerability reports should be directed to the Intent security team.

Security: contact@int.yt

General support: support@int.yt

Community: Intent Discord →