Sign-in and passwords
- Use a unique password that is not used on another service.
- Access GuestPost only through an expected GuestPost website or account portal.
- Never send a password, reset token, session value, or one-time code to support.
Password recovery
Password-reset requests use a generic response so the public form does not reveal whether an email address has an account. Reset links should be treated as secrets and used only on the device where recovery was requested.
Organization access
Organization owners should grant the minimum role required and remove access when a member no longer needs it. Interface visibility does not replace server authorization; protected actions are checked again by the service.
Suspension and sessions
Account suspension is an audited lifecycle. Active sessions can be revoked when an account is suspended or a security event requires containment. Restoring account eligibility does not restore an old session.
Report suspicious activity
Use authenticated support for account-specific activity. For a suspected vulnerability, email security@guestpost.cc. For suspected marketplace fraud, email fraud@guestpost.cc.
Responsible security research
Good-faith reports should avoid privacy violations, data destruction, service disruption, social engineering, and access beyond what is necessary to demonstrate the issue. Include reproduction steps and affected URLs without sending unrelated personal data.