SECURITY POLICY
Infrastructure security, data protection, vulnerability reporting, and incident response.
1. Infrastructure Security
- Network-level DDoS mitigation on all services
- Intrusion detection and prevention systems (IDS/IPS)
- Regular vulnerability scanning and patch management
- Network segmentation and isolation between tenants
- Hardware firewalls at network edge
2. Data Protection
- Traffic encrypted in transit using TLS 1.2+
- Passwords hashed with bcrypt/argon2 (never stored in plaintext)
- Database encryption at rest for sensitive data
- Regular automated backups with encryption
- Secure key management for encryption keys
3. Access Control
- Principle of least privilege for all staff access
- Multi-factor authentication required for all administrative access
- Access logging and audit trails for sensitive operations
- Regular access reviews and deprovisioning procedures
- Customer data access limited to support necessity only
4. Vulnerability Reporting
VerticeHost encourages responsible disclosure of security vulnerabilities. Report vulnerabilities to security@verticehost.com.
- We acknowledge reports within 48 hours
- We provide regular updates on investigation progress
- We do not pursue legal action against good-faith researchers
- Coordinated disclosure timeline: 90 days default
5. Incident Response
- 24/7 monitoring and alerting for security events
- Defined incident response procedures and escalation paths
- Customer notification within 72 hours of confirmed data breach (where legally required)
- Post-incident review and remediation tracking
6. Customer Responsibilities
- Maintain security of applications, containers, and OS
- Apply security patches promptly
- Use strong, unique passwords and enable 2FA
- Restrict access by IP where possible
- Monitor for unusual activity in your services
