SECURITY POLICY

Last Updated: 28 August 2026

Infrastructure security, data protection, vulnerability reporting, and incident response.

1. Infrastructure Security

  • Network-level DDoS mitigation on all services
  • Intrusion detection and prevention systems (IDS/IPS)
  • Regular vulnerability scanning and patch management
  • Network segmentation and isolation between tenants
  • Hardware firewalls at network edge

2. Data Protection

  • Traffic encrypted in transit using TLS 1.2+
  • Passwords hashed with bcrypt/argon2 (never stored in plaintext)
  • Database encryption at rest for sensitive data
  • Regular automated backups with encryption
  • Secure key management for encryption keys

3. Access Control

  • Principle of least privilege for all staff access
  • Multi-factor authentication required for all administrative access
  • Access logging and audit trails for sensitive operations
  • Regular access reviews and deprovisioning procedures
  • Customer data access limited to support necessity only

4. Vulnerability Reporting

VerticeHost encourages responsible disclosure of security vulnerabilities. Report vulnerabilities to security@verticehost.com.

  • We acknowledge reports within 48 hours
  • We provide regular updates on investigation progress
  • We do not pursue legal action against good-faith researchers
  • Coordinated disclosure timeline: 90 days default

5. Incident Response

  • 24/7 monitoring and alerting for security events
  • Defined incident response procedures and escalation paths
  • Customer notification within 72 hours of confirmed data breach (where legally required)
  • Post-incident review and remediation tracking

6. Customer Responsibilities

  • Maintain security of applications, containers, and OS
  • Apply security patches promptly
  • Use strong, unique passwords and enable 2FA
  • Restrict access by IP where possible
  • Monitor for unusual activity in your services