Information Security & Disclosure
Our commitment to client data integrity, transport encryption, and responsible vulnerability disclosure.
1. Security Architecture & Data Safeguards
Home Finders operates on a hardened, static web architecture designed to eliminate database injection, cross-site scripting (XSS), and unauthorized privilege escalation. Key safeguards include:
- Transport Layer Security (TLS 1.3): Strict HTTPS enforcement across all endpoints with automated 301 redirection.
- HTTP Security Headers: Comprehensive implementation of
X-Content-Type-Options: nosniff,X-Frame-Options: SAMEORIGIN,Referrer-Policy: strict-origin-when-cross-origin, and HSTS. - Zero Client Token Storage: We do not store sensitive authentication credentials or user passwords on client browsers.
- Direct Bank Payment Routing: All property transactions are executed directly with housing developers through official crossed pay orders. Home Finders never requests debit card PINs or online banking passwords.
2. Coordinated Vulnerability Disclosure (RFC 9116)
We welcome security researchers and ethical hackers to notify us of any identified technical flaws. If you believe you have discovered a vulnerability on homefinderspk.com:
Security Contact: security@homefinderspk.com
Canonical Policy File: /.well-known/security.txt
Response SLA: We acknowledge receipt within 48 business hours and commit to resolving critical flaws within 7 business days.
3. Ground Rules
Please refrain from executing denial-of-service (DoS/DDoS) attacks, social engineering of employees, or accessing data belonging to other clients. All assessments must be conducted within the scope of responsible research.