Report abuse
Sites on *.juudd.app, and customer domains pointed at them, are published by the people who own them. If one of them is phishing, malware, or pretending to be someone it is not, tell us and we will take it off the air.
Where to send it
abuse@juudd.com. A person reads it.
If you have found a vulnerability in this platform rather than a bad site on it, security@juudd.com is the address for that, and /.well-known/security.txt is the machine-readable version of this paragraph.
What to include
One report can be acted on in a single pass if it carries these. None of them is mandatory; the first one is close.
- The full URL, including the path. What is taken down is a site, and the hostname is what names it.
- What is wrong with it, in a sentence. "Impersonates a bank's login page" is enough.
- When you saw it, and whether it is still live for you. Some of these are served to some visitors and not others.
- A screenshot or the page source, if you have one. Useful for the case where the page is already gone by the time it is read.
What we can do
Stop serving it. That is a real remedy here and not a euphemism: the site's code is removed from the network that serves it, and the hostname stops answering. An operator can do it for one site, or for every site an account owns at once. Both are reserved by the terms, which forbid unlawful content, malware, phishing and impersonation by name.
What we do not do is delete. Every version a customer ever deployed stays stored, permanently and on purpose - it is what makes a rollback possible, and it is promised to them. So "stop serving" is exactly what enforcement is here, and it is complete: nothing is being served, and the record of what was served survives for anyone who later has a right to ask about it.
What we cannot do
- Anything about a domain we do not serve. A customer can point their own domain at a site here. We can detach it from this platform; we are not its registrar and cannot take the name away.
- Tell you who owns a site. Sign-in identity belongs to the customer's identity provider and is not ours to hand out. A lawful request from someone entitled to make one is a different path, and the address above reaches a person who will read it.
- Act on a site that is merely disagreeable. The line this platform enforces is the one written in the terms.
What happens next
The address reaches a person, not a queue. Every act taken is written into the platform's own permanent record, under the account it was taken against and naming the operator who took it - so a decision made in a hurry can be read back later, by us or by the customer it was made about.
If a report was wrong, putting a site back is one act and it returns the exact version that was live when it stopped.