PrivacyGuard DNS - Security Policy
Security Commitment
At PrivacyGuard DNS, we take the security of our users and systems very seriously. This document outlines our security practices, vulnerability disclosure policy, and how we protect your data.
Data Protection
What We Collect
- Anonymous Usage Statistics: Aggregate data about DNS queries (no personal information)
- Server Logs: Temporary logs for troubleshooting (automatically deleted within 24 hours)
- Analytics: Basic visitor statistics (country, browser type)
What We DON'T Collect
- β Your browsing history
- β Your IP address (anonymized immediately)
- β Any personal information
- β Login credentials
- β Financial information
Data Retention
| Data Type | Retention Period | Purpose |
|---|---|---|
| Anonymous query logs | 24 hours | Performance optimization |
| Server logs | 24 hours | Troubleshooting |
| Analytics | 30 days | Service improvement |
Infrastructure Security
Server Security
- Encrypted Connections: All DNS queries support DoH (DNS over HTTPS) and DoT (DNS over TLS)
- Regular Updates: Security patches applied within 24 hours
- Firewall Protection: Enterprise-grade firewall rules
- DDoS Protection: Advanced mitigation systems
Network Security
Layer 1: Edge DDoS Protection
Layer 2: Firewall & Rate Limiting
Layer 3: Application Security
Layer 4: DNS Query Validation
Encryption Standards
| Protocol | Status | Description |
|---|---|---|
| DoH (DNS over HTTPS) | β Enabled | Encrypted DNS queries |
| DoT (DNS over TLS) | β Enabled | TLS-encrypted DNS |
| DNSSEC | β Enabled | DNS signature validation |
| TLS 1.3 | β Enabled | Latest transport security |
Vulnerability Disclosure
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly:
- Do NOT disclose the vulnerability publicly
- Do NOT attempt to exploit the vulnerability
- Do NOT access data beyond what is necessary to confirm the issue
Report a Vulnerability
Email: security@privacyguard.dns
Include in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Your contact information
Response Timeline
| Action | Timeline |
|---|---|
| Initial acknowledgment | 24 hours |
| Vulnerability assessment | 48 hours |
| Fix deployment | 7-30 days (severity dependent) |
| Public disclosure | After fix deployment |
Best Practices for Users
Enable Additional Security
- Use DoH/DoT: Configure your device to use encrypted DNS
- Enable DNSSEC: Validates DNS response authenticity
- Regular Updates: Keep your device and browser updated
- Use HTTPS: Always use secure connections
Recommended Security Settings
DNS Configuration:
Primary: 94.140.14.14
Secondary: 94.140.15.15
Protocol: DNS-over-HTTPS
DNSSEC: Enabled
Advanced:
QNAME Minimization: Enabled
EDNS Client Subnet: Disabled
Compliance
Standards Compliance
- GDPR: Compliant with EU data protection regulations
- CCPA: Compliant with California privacy laws
- SOC 2: In preparation
Third-Party Audits
- Annual security audits by independent firms
- Penetration testing quarterly
- Continuous monitoring
Incident Response
Security Incident Types
| Level | Description | Response Time |
|---|---|---|
| Critical | Data breach, system compromise | 1 hour |
| High | Vulnerability exploitation | 4 hours |
| Medium | Service degradation | 24 hours |
| Low | Non-critical issues | 72 hours |
Incident Notification
If a security incident occurs:
- Users will be notified within 72 hours
- Detailed report will be published
- Remediation steps will be provided
- Post-incident review will be conducted
Contact Security Team
Security Email: security@privacyguard.dns PGP Key: [Link to PGP key] Response Time: 24-48 hours
For non-security issues, contact: support@privacyguard.dns