Legal
Hostwover Legal Center

Policies, agreements, and legal information for using Hostwover services.

Information Security Policy

Language note

The English version of Hostwover's legal agreements and policies is the authoritative version. Translated versions are provided for convenience. If there is any conflict between translations, the English version shall prevail.

Effective date: August 14, 2026

Last updated: August 14, 2026

1. Introduction

Security is a fundamental part of the way Hostwover designs, operates, and delivers its Services.

Hostwover is committed to protecting the confidentiality, integrity, availability, and resilience of information, systems, infrastructure, customer accounts, and Services under our control.

This Information Security Policy describes the principles, safeguards, responsibilities, and security practices that Hostwover applies or seeks to apply across its operations.

Because security threats, technologies, and regulatory requirements evolve over time, Hostwover continuously reviews and improves its security practices according to identified risks, technical requirements, operational needs, and applicable law.

2. Scope

This Policy applies to information systems, infrastructure, applications, personnel, processes, and Services operated or controlled by Hostwover, including, where applicable:

  • the Hostwover website.
  • customer accounts.
  • customer dashboards.
  • internal administrative systems.
  • APIs.
  • databases.
  • domain-related systems.
  • Web Hosting Services.
  • VPS Services.
  • VDS Services.
  • Professional Email provisioning.
  • Google Workspace provisioning and management.
  • Wover AI.
  • billing and checkout systems.
  • customer-support systems.
  • monitoring and logging systems.
  • backup and recovery systems.
  • software-development environments.
  • networks and infrastructure.
  • integrations with authorized third-party providers; and
  • other technology used to operate Hostwover.

Third-party platforms that Hostwover does not directly control are also subject to the security practices and contractual obligations of their respective providers.

3. Security Objectives

Hostwover's security program is designed around four primary objectives.

Confidentiality

Information should only be accessible to authorized persons and systems for legitimate purposes.

Integrity

Information and systems should be protected against unauthorized or accidental alteration.

Availability

Systems and information required to deliver our Services should remain reasonably available and recoverable.

Resilience

Hostwover seeks to design and operate Services in a way that allows us to prevent, withstand, respond to, and recover from security incidents and technical failures.

4. Security Governance

Hostwover manages information security as an ongoing operational responsibility.

Security responsibilities may include:

  • identifying security risks.
  • assessing threats and vulnerabilities.
  • implementing appropriate safeguards.
  • managing user and administrative access.
  • monitoring systems.
  • responding to security incidents.
  • maintaining backups.
  • reviewing third-party providers.
  • protecting software-development processes.
  • training personnel.
  • reviewing security policies.
  • complying with applicable legal requirements; and
  • continuously improving security controls.

Security decisions may be based on the sensitivity of the information, potential impact of compromise, technical feasibility, applicable contractual obligations, regulatory requirements, and identified threats.

5. Risk Management

Hostwover applies a risk-based approach to information security.

Risks may be evaluated based on factors including:

  • likelihood of occurrence.
  • potential impact.
  • affected systems.
  • affected users.
  • type and sensitivity of information.
  • business impact.
  • service availability.
  • regulatory impact.
  • fraud risk.
  • abuse risk.
  • infrastructure exposure; and
  • availability of reasonable mitigations.

Hostwover may implement additional controls where a system or processing activity creates increased security risk.

6. Security by Design

Security should be considered during the design and development of Hostwover products and Services, rather than only after deployment.

Where appropriate, new systems and features should be reviewed for matters such as:

  • authentication.
  • authorization.
  • data access.
  • Personal Data.
  • input validation.
  • API security.
  • session management.
  • secrets.
  • encryption.
  • error handling.
  • logging.
  • abuse risks.
  • third-party dependencies.
  • data retention.
  • infrastructure exposure; and
  • recovery requirements.

Security requirements may differ according to the type and risk level of the feature.

7. Shared Responsibility

Information security is a shared responsibility between Hostwover, our infrastructure and technology providers, and our customers.

Hostwover is responsible for securing the systems, applications, and infrastructure components that are under Hostwover's control.

Customers are responsible for securing the systems, credentials, applications, content, configurations, and resources under their control.

The exact division of responsibility depends on the Service being used.

For example, a customer operating an unmanaged VPS or VDS generally has greater responsibility for operating-system and application security than a customer using a managed platform.

Nothing in this Policy changes the responsibilities defined in the applicable Service Agreement or Terms of Service.

8. Information and Asset Management

Hostwover seeks to identify and appropriately manage information and technology assets that are important to the operation and security of our Services.

Assets may include:

  • servers.
  • virtual machines.
  • applications.
  • databases.
  • source code.
  • network infrastructure.
  • domain systems.
  • credentials.
  • encryption material.
  • customer information.
  • logs.
  • backups.
  • APIs.
  • third-party integrations; and
  • internal administrative systems.

Security controls may vary according to the sensitivity and importance of the asset.

9. Information Classification

Information may be classified according to its sensitivity and security requirements.

Hostwover may use classifications such as:

Public

Information intended for public disclosure.

Internal

Operational information intended primarily for authorized Hostwover personnel.

Confidential

Information requiring protection from unauthorized access, including certain customer, business, support, and operational information.

Restricted

Highly sensitive information requiring stronger access controls, which may include:

  • authentication secrets.
  • cryptographic material.
  • certain security information.
  • identity-verification documents.
  • sensitive Personal Data.
  • privileged credentials; and
  • certain fraud or security-investigation records.

Access to information should be limited according to legitimate business requirements.

10. Identity and Access Management

Hostwover seeks to apply appropriate controls to determine who or what may access systems and information.

Access-management practices may include:

  • individual user accounts.
  • role-based access.
  • least-privilege access.
  • authentication requirements.
  • multi-factor authentication for appropriate privileged systems.
  • access reviews.
  • account disabling when access is no longer required.
  • administrative access restrictions.
  • session controls.
  • audit logging; and
  • credential-management requirements.

Personnel should only have access necessary to perform their authorized responsibilities.

11. Privileged and Administrative Access

Privileged access presents increased security risk and is therefore subject to additional controls where appropriate.

Hostwover seeks to restrict administrative access to authorized personnel who require such access for legitimate operational purposes.

Privileged actions may include:

  • infrastructure administration.
  • database administration.
  • account administration.
  • billing administration.
  • security investigation.
  • support escalation.
  • deployment.
  • recovery operations; and
  • configuration changes.

Administrative access may be logged, monitored, restricted, reviewed, or revoked according to security requirements.

Shared privileged accounts should be avoided where individual accountability can reasonably be maintained.

12. Customer Account Security

Hostwover implements measures designed to protect customer accounts against unauthorized access.

These measures may include:

  • secure authentication.
  • password requirements.
  • password hashing.
  • authentication rate limiting.
  • session-management controls.
  • verification for sensitive actions.
  • suspicious-activity detection.
  • password-reset protection.
  • access logging.
  • multi-factor authentication where available; and
  • additional verification for elevated-risk activities.

Customers are responsible for protecting their own credentials and devices.

13. Password Security

Hostwover does not intentionally store customer account passwords in readable plain-text form.

Passwords should be protected using appropriate one-way password-hashing mechanisms.

Customers should:

  • use strong passwords.
  • use unique passwords.
  • avoid sharing passwords.
  • avoid reusing passwords from other services.
  • protect recovery channels.
  • use multi-factor authentication where available; and
  • immediately change credentials they believe may have been compromised.

Hostwover personnel should never request a customer's full account password through email, chat, telephone, or support tickets.

14. Secrets and Credentials

Sensitive credentials and secrets should not be stored or transmitted unnecessarily.

These may include:

  • API keys.
  • database credentials.
  • private keys.
  • access tokens.
  • signing keys.
  • payment-provider secrets.
  • service credentials.
  • administrative passwords; and
  • encryption keys.

Where appropriate, Hostwover may use protected configuration systems, environment controls, secret-management mechanisms, access restrictions, encryption, rotation procedures, or other safeguards.

Secrets should not be intentionally committed to public source-code repositories.

15. Encryption

Hostwover uses or seeks to use appropriate cryptographic protections where they are reasonably necessary to protect sensitive information.

This may include encryption:

  • during transmission.
  • between appropriate systems.
  • for sensitive stored information.
  • for backups where appropriate.
  • for administrative connections; and
  • for protected communications.

Hostwover generally uses secure HTTPS/TLS connections for customer-facing web Services where technically applicable.

Cryptographic measures are reviewed according to security requirements and technological developments.

16. Network Security

Hostwover uses security measures intended to protect networks and infrastructure from unauthorized access and malicious activity.

Depending on the Service and environment, controls may include:

  • network segmentation.
  • firewalls.
  • access-control rules.
  • traffic filtering.
  • rate limiting.
  • secure administrative protocols.
  • restricted management interfaces.
  • monitoring.
  • abuse detection.
  • DDoS-related protections.
  • provider-level network protections; and
  • other defensive controls.

For security reasons, Hostwover does not publicly disclose detailed network architecture, firewall configurations, filtering rules, internal addressing, or other sensitive network-security information.

17. Infrastructure Security

Hostwover relies on a combination of Hostwover-managed systems and authorized infrastructure providers.

Infrastructure protections may include:

  • controlled administrative access.
  • hardened configurations.
  • secure provisioning.
  • monitoring.
  • security updates.
  • access logging.
  • infrastructure isolation.
  • backup and recovery measures.
  • capacity monitoring; and
  • security controls supplied by our infrastructure providers.

The exact controls depend on the Service and underlying environment.

18. VPS and VDS Security

VPS and VDS Services provide customers with significant control over their server environments.

Unless expressly stated otherwise in the applicable Service description or agreement, customers are responsible for securing software and configurations inside their VPS or VDS.

Customer responsibilities may include:

  • protecting root and administrative credentials.
  • keeping the operating system updated.
  • installing security patches.
  • configuring firewalls.
  • securing SSH or remote administration.
  • protecting applications.
  • protecting databases.
  • securing web servers.
  • managing users and permissions.
  • removing unnecessary services.
  • monitoring installed software.
  • maintaining application-level backups where required; and
  • responding to vulnerabilities affecting customer-installed software.

Hostwover may implement infrastructure-level safeguards, but these safeguards do not replace the customer's responsibility for systems under the customer's control.

19. Web Hosting Security

For Web Hosting Services, Hostwover and its hosting technology providers may manage portions of the underlying hosting environment.

Customers remain responsible for matters within their control, including:

  • website software.
  • application credentials.
  • CMS accounts.
  • plugins.
  • themes.
  • custom code.
  • uploaded files.
  • user permissions; and
  • the security of third-party applications they install or operate.

Customers should promptly update applications, plugins, themes, dependencies, and other website software when security updates become available.

20. Domain Security

Hostwover applies security controls designed to protect domain-related operations.

Depending on the action and available functionality, these controls may include:

  • authenticated account access.
  • ownership verification.
  • email verification.
  • transfer authorization.
  • authorization codes.
  • registry or registrar locks.
  • fraud monitoring.
  • additional verification for sensitive domain actions; and
  • activity records.

Customers are responsible for maintaining accurate domain contact information and protecting the email account and Hostwover account associated with their domains.

A compromised customer email account may affect the security of domain-related actions.

21. Professional Email Security

Professional Email Services may involve Hostwover and authorized email-platform providers.

Security responsibilities may include:

  • account authentication.
  • mailbox credentials.
  • administrative access.
  • domain configuration.
  • service provisioning.
  • provider security controls; and
  • abuse prevention.

Customers are responsible for protecting mailbox credentials and for the secure use of their email accounts.

Customers should use strong, unique passwords and any additional security controls made available by the underlying provider.

22. Google Workspace Security

Where Hostwover provides or resells Google Workspace Services, elements of the Service are operated by Google or applicable authorized distribution channels.

Hostwover may process or transmit limited information necessary for:

  • provisioning.
  • subscription management.
  • billing.
  • domain verification.
  • support; and
  • Service administration.

Security of the underlying Google Workspace platform is also governed by Google's applicable systems, terms, security practices, and customer configuration.

Customers remain responsible for their Workspace administrator accounts, user permissions, authentication settings, sharing controls, and other configurations under their control.

23. Wover AI Security

Hostwover applies security considerations to Wover AI and other AI-powered functionality.

Depending on the feature, safeguards may include:

  • authentication.
  • access control.
  • abuse prevention.
  • input handling.
  • output handling.
  • request monitoring.
  • usage restrictions.
  • provider controls.
  • data minimization; and
  • limitations on access to account information.

Users should never intentionally submit the following through an AI interface unless explicitly required for a supported and protected purpose:

  • passwords.
  • private cryptographic keys.
  • complete payment-card information.
  • CVV codes.
  • database passwords.
  • API secrets.
  • authentication tokens.
  • session cookies.
  • recovery codes; or
  • other credentials capable of granting access to a system.

AI-generated output should not be treated as a security authorization or as a substitute for appropriate technical review.

24. Secure Software Development

Hostwover seeks to incorporate security into software-development practices.

Controls may include:

  • code review.
  • dependency management.
  • input validation.
  • output encoding.
  • authentication controls.
  • authorization controls.
  • secure session handling.
  • error handling.
  • API security.
  • secure configuration.
  • secrets management.
  • automated security checks.
  • testing.
  • dependency vulnerability review; and
  • controlled deployment processes.

Security requirements may be adjusted according to the risk and sensitivity of the system being developed.

25. Development and Production Separation

Hostwover seeks to maintain appropriate separation between development and production environments.

Production credentials and sensitive customer information should not be unnecessarily copied into development environments.

Where production-like information is required for testing, Hostwover should use minimized, anonymized, synthetic, or otherwise appropriately protected data where reasonably possible.

Access to production systems should be limited to personnel with a legitimate operational need.

26. Change Management

Changes to important production systems should be controlled according to their potential impact.

Depending on the change, controls may include:

  • peer review.
  • testing.
  • authorization.
  • deployment controls.
  • rollback planning.
  • monitoring after deployment; and
  • documentation.

Emergency changes may use an accelerated process when necessary to protect security, restore availability, or address a critical incident.

27. Vulnerability Management

Hostwover seeks to identify, evaluate, prioritize, and remediate security vulnerabilities affecting systems under our control.

Vulnerability-management practices may include:

  • dependency monitoring.
  • security advisories.
  • software updates.
  • patch management.
  • automated scanning.
  • manual review.
  • penetration testing where appropriate.
  • infrastructure review.
  • application testing.
  • responsible vulnerability reports; and
  • risk-based remediation.

Remediation priority may depend on:

  • severity.
  • exploitability.
  • system exposure.
  • affected data.
  • known exploitation.
  • available mitigation.
  • business impact; and
  • affected customers.

28. Security Updates and Patch Management

Hostwover seeks to apply security updates to systems under our responsibility within a period appropriate to the associated risk.

Critical vulnerabilities may receive accelerated remediation.

Some updates may require:

  • testing.
  • scheduled maintenance.
  • temporary Service interruption.
  • compatibility review; or
  • coordination with third-party providers.

Customers remain responsible for patching software and operating systems under their own administrative control.

29. Logging

Hostwover may maintain logs necessary to operate, secure, investigate, and improve our Services.

Security-related logs may include events such as:

  • successful and failed authentication.
  • administrative actions.
  • authorization failures.
  • account changes.
  • configuration changes.
  • Service provisioning.
  • security alerts.
  • API activity.
  • application errors.
  • system events.
  • suspicious activity; and
  • abuse-related events.

Logs are subject to access controls and retention policies appropriate to their purpose.

30. Sensitive Information in Logs

Hostwover seeks to avoid intentionally recording sensitive authentication information in application logs.

Information that should not be unnecessarily logged includes:

  • passwords.
  • private keys.
  • complete authentication tokens.
  • complete payment-card numbers.
  • CVV codes.
  • database passwords.
  • session secrets; and
  • other highly sensitive credentials.

Where sensitive identifiers are needed for troubleshooting, they may be masked, truncated, hashed, or otherwise minimized where appropriate.

31. Monitoring and Detection

Hostwover may monitor systems and Services for indicators of:

  • unauthorized access.
  • account compromise.
  • suspicious authentication.
  • malware.
  • phishing.
  • spam.
  • abuse.
  • unusual traffic.
  • application failures.
  • infrastructure failures.
  • payment fraud.
  • security vulnerabilities; and
  • other potentially harmful activity.

Monitoring may be automated or manual.

Security alerts may result in investigation, verification requests, access restrictions, Service suspension, credential reset, or other protective actions where appropriate.

32. Fraud Prevention

Hostwover may use technical and operational controls to identify and prevent fraudulent activity.

These controls may consider information such as:

  • transaction activity.
  • account history.
  • authentication patterns.
  • IP information.
  • device information.
  • order information.
  • Service usage.
  • previous abuse.
  • payment-provider signals; and
  • other legitimate risk indicators.

Where suspicious activity is identified, Hostwover may request additional verification or restrict an action according to our Terms of Service and applicable law.

33. Abuse Prevention

Hostwover Services must not be used to compromise the security of Hostwover, other customers, third parties, or the Internet.

Security-related prohibited activities are further defined in Hostwover's:

  • Acceptable Use Policy.
  • Acceptable Use Agreement; and
  • Abuse Handling Policy.

Hostwover may investigate suspected abuse and take measures necessary to protect customers, infrastructure, third parties, and our Services.

34. Malware and Malicious Content

Hostwover may use automated or manual mechanisms to detect, restrict, or investigate malicious activity involving our Services.

This may include:

  • malware.
  • phishing.
  • credential theft.
  • malicious scripts.
  • botnets.
  • unauthorized cryptomining.
  • exploitation.
  • command-and-control infrastructure.
  • spam infrastructure.
  • malicious redirects; and
  • other harmful activity.

Where permitted by applicable agreements and law, Hostwover may suspend, isolate, restrict, or remove access to systems involved in harmful activity.

35. Backups

Hostwover may maintain backups of systems and information where appropriate to the relevant Service.

Backup practices may include:

  • automated backup schedules.
  • access restrictions.
  • retention periods.
  • backup integrity controls.
  • protected storage.
  • restoration procedures; and
  • periodic recovery testing.

Backup availability, frequency, scope, and retention depend on the specific Service.

Unless expressly included in a Service description or agreement, customers should not assume that Hostwover maintains a complete backup of customer-controlled data.

Customers remain responsible for maintaining independent backups appropriate to their own business and risk requirements.

36. Recovery and Business Continuity

Hostwover seeks to maintain reasonable measures for recovering from security incidents, system failures, and other disruptions.

Measures may include:

  • backups.
  • infrastructure redundancy where available.
  • recovery procedures.
  • provider escalation.
  • monitoring.
  • incident-management processes.
  • service restoration procedures; and
  • business-continuity planning.

Recovery priorities may consider:

  • customer impact.
  • security impact.
  • affected Services.
  • system dependencies.
  • data integrity.
  • operational risk; and
  • availability of recovery resources.

37. Security Incident Response

Hostwover maintains or seeks to maintain procedures for responding to security incidents.

Incident-response activities may include:

  1. detection.
  2. verification.
  3. classification.
  4. containment.
  5. evidence preservation.
  6. investigation.
  7. eradication.
  8. recovery.
  9. customer or regulatory notification where required.
  10. root-cause analysis; and
  11. corrective action.

Hostwover may involve infrastructure providers, cybersecurity specialists, legal advisers, law-enforcement authorities, regulators, or other appropriate parties where necessary.

38. Personal Data Breaches

Security incidents involving Personal Data are also handled in accordance with Hostwover's privacy and data-protection obligations.

Where legally required, Hostwover will notify:

  • the applicable data-protection authority.
  • affected data subjects; or
  • other legally required parties

within the periods required by applicable law.

Additional information regarding Personal Data is provided in Hostwover's Privacy Policy and Privacy / Data Protection Policy.

39. Security Incident Records

Hostwover may maintain internal records concerning security incidents.

Records may include:

  • detection time.
  • awareness time.
  • affected system.
  • nature of the incident.
  • affected information.
  • containment actions.
  • investigation results.
  • notifications.
  • remediation.
  • root cause.
  • lessons learned; and
  • closure information.

Access to security-incident records may be restricted because they can contain sensitive information.

40. Third-Party and Supplier Security

Hostwover depends on third-party technology and infrastructure providers to deliver certain Services.

Providers may include:

  • data-center providers.
  • infrastructure providers.
  • domain registrars.
  • domain registries.
  • email providers.
  • productivity-service providers.
  • payment processors.
  • cloud providers.
  • AI providers.
  • analytics services.
  • communications providers.
  • security services; and
  • other technology suppliers.

Hostwover seeks to consider security and privacy requirements when selecting and managing providers that process important or sensitive information.

The level of review may depend on the type of Service and risk involved.

41. Third-Party Access

Access provided to contractors, vendors, or other authorized third parties should be limited to what is reasonably necessary for the approved purpose.

Controls may include:

  • confidentiality requirements.
  • contractual security obligations.
  • restricted access.
  • temporary access.
  • approval.
  • authentication requirements.
  • monitoring.
  • logging; and
  • revocation when access is no longer needed.

42. Supply Chain Security

Hostwover recognizes that software libraries, infrastructure providers, third-party integrations, and service providers may introduce security risk.

Hostwover therefore seeks to consider risks associated with:

  • software dependencies.
  • packages.
  • external APIs.
  • hosting providers.
  • deployment systems.
  • third-party scripts.
  • authentication providers.
  • payment providers.
  • AI providers; and
  • other technology dependencies.

Where significant supplier risk is identified, Hostwover may implement additional controls, replace a provider, restrict an integration, or take other reasonable action.

43. Personnel Security

Personnel with access to Hostwover systems or information are expected to follow applicable security and confidentiality requirements.

Depending on role and risk, measures may include:

  • confidentiality obligations.
  • access restrictions.
  • security awareness.
  • secure credential requirements.
  • multi-factor authentication.
  • role-based permissions.
  • administrative logging.
  • security training.
  • access reviews; and
  • offboarding procedures.

Personnel are expected to report suspected security incidents without unreasonable delay.

44. Personnel Offboarding

When a person's authorized relationship with Hostwover ends or their responsibilities materially change, access should be reviewed and removed or modified as appropriate.

Actions may include:

  • disabling user accounts.
  • removing privileged access.
  • revoking administrative access.
  • revoking remote-access permissions.
  • removing repository access.
  • removing support-system access.
  • removing email access.
  • revoking or rotating credentials.
  • revoking API tokens; and
  • reviewing assigned assets.

The required measures depend on the person's previous level of access.

45. Physical Security

Some Hostwover infrastructure may be operated within facilities controlled by third-party data-center and infrastructure providers.

Physical security of those facilities is therefore partly dependent on the controls maintained by the relevant provider.

Such controls may include restricted physical access, surveillance, environmental protections, power controls, network protections, and other data-center safeguards.

Hostwover does not publicly disclose sensitive physical-security arrangements that could weaken security.

46. Remote Access

Administrative remote access to sensitive Hostwover systems should use appropriately protected methods.

Depending on the environment, this may include:

  • secure encrypted protocols.
  • authenticated access.
  • SSH keys.
  • VPN or protected administrative networks.
  • multi-factor authentication.
  • IP restrictions.
  • time-limited access; or
  • other appropriate controls.

Unencrypted administrative protocols should not be used where secure alternatives are reasonably available.

47. Source Code Security

Access to private Hostwover source code should be restricted to authorized personnel and systems.

Controls may include:

  • authenticated repositories.
  • access permissions.
  • branch controls.
  • code review.
  • dependency monitoring.
  • deployment restrictions.
  • secret scanning; and
  • activity logging.

Sensitive production secrets should not be intentionally stored directly in source code.

48. API Security

Hostwover APIs may be protected through controls such as:

  • authentication.
  • authorization.
  • access tokens.
  • rate limiting.
  • request validation.
  • input validation.
  • logging.
  • abuse detection.
  • restricted scopes.
  • permission checks; and
  • secure transport.

Possession of a valid API credential does not authorize use outside the permissions associated with that credential.

Customers are responsible for protecting their own API credentials.

49. Payment Security

Payments may be processed using authorized third-party payment processors.

Where payment information is entered directly into a payment provider's protected environment, Hostwover seeks to minimize the payment-card information received or stored directly by Hostwover.

Hostwover does not intentionally require storage of a customer's payment-card CVV after authorization.

Payment-related systems may also use fraud-prevention and transaction-monitoring controls.

Payment providers remain responsible for the security obligations applicable to their own payment-processing environments.

50. Privacy and Information Security

Information security and privacy are related but distinct responsibilities.

Hostwover seeks to protect Personal Data through measures appropriate to:

  • the nature of the information.
  • processing purpose.
  • associated risk.
  • storage location.
  • access requirements.
  • applicable law; and
  • available technology.

Detailed information about Hostwover's processing of Personal Data is available in:

  • Privacy Policy.
  • Privacy / Data Protection Policy; and
  • Cookie Policy.

51. Data Minimization

Hostwover seeks to avoid collecting or retaining information that is not reasonably necessary for a legitimate purpose.

Reducing unnecessary information can reduce the potential impact of a security incident.

Where appropriate, information may be:

  • deleted.
  • anonymized.
  • masked.
  • truncated.
  • restricted.
  • aggregated; or
  • otherwise minimized.

52. Security Testing

Hostwover may perform security testing on systems that we own or are authorized to test.

Testing may include:

  • automated vulnerability scanning.
  • dependency scanning.
  • code analysis.
  • configuration review.
  • manual testing.
  • penetration testing.
  • authentication testing.
  • authorization testing.
  • API testing; and
  • infrastructure review.

Testing methods and frequency may vary according to risk, system criticality, technical changes, and available resources.

53. No Unauthorized Security Testing

Customers and third parties must not perform disruptive, destructive, or unauthorized security testing against Hostwover systems.

Prohibited activity may include unauthorized:

  • denial-of-service testing.
  • traffic flooding.
  • destructive exploitation.
  • data access.
  • social engineering.
  • malware deployment.
  • credential attacks.
  • physical attacks.
  • access to another customer's environment; or
  • actions intended to degrade Service availability.

Good-faith security research must comply with Hostwover's Responsible Disclosure Policy.

54. Responsible Security Disclosure

Hostwover encourages responsible reporting of suspected security vulnerabilities.

Researchers should:

  • act in good faith.
  • avoid accessing unnecessary customer information.
  • avoid damaging systems or information.
  • avoid degrading Service availability.
  • avoid privacy violations.
  • provide sufficient technical information to reproduce the issue; and
  • allow Hostwover a reasonable opportunity to investigate and remediate the issue before public disclosure.

Full requirements are provided in Hostwover's:

Responsible Disclosure Policy

55. Security Reports

Security concerns should be reported privately.

For general security-related concerns, customers may contact:

Hostwover Support

Email: [email protected]

Website: hostwover.com

When reporting a suspected vulnerability or security incident, use a subject such as:

Security Report

Do not publicly disclose sensitive vulnerability details before Hostwover has had a reasonable opportunity to investigate.

Hostwover may publish a dedicated security contact address separately.

56. Information to Include in a Security Report

Where possible, a security report should include:

  • affected URL or Service.
  • vulnerability type.
  • steps to reproduce.
  • expected behavior.
  • observed behavior.
  • security impact.
  • relevant request or response information.
  • screenshots where useful.
  • proof of concept where safe; and
  • contact information for follow-up.

Researchers must avoid including Personal Data belonging to unrelated individuals unless strictly necessary to demonstrate the issue.

57. Customer Security Responsibilities

Customers play an important role in protecting their accounts and Services.

Customers should:

  • use strong and unique passwords.
  • enable available multi-factor authentication.
  • protect email accounts used for account recovery.
  • keep contact details current.
  • secure API credentials.
  • protect private keys.
  • update software.
  • patch systems.
  • configure appropriate firewalls.
  • limit administrative access.
  • maintain independent backups.
  • remove unused accounts.
  • review account activity.
  • investigate security warnings.
  • avoid installing untrusted software.
  • follow applicable Service security guidance; and
  • promptly report suspected compromise.

58. Customer-Owned Applications and Content

Hostwover generally cannot guarantee the security of software, code, plugins, applications, or content installed or developed by customers.

Customers are responsible for evaluating the security of:

  • custom code.
  • CMS installations.
  • plugins.
  • themes.
  • third-party packages.
  • APIs.
  • databases.
  • uploaded software.
  • containers.
  • services; and
  • other workloads they control.

A vulnerability within customer-controlled software does not necessarily indicate a vulnerability within Hostwover infrastructure.

59. Compromised Customer Services

If Hostwover reasonably believes a customer Service has been compromised or is creating a material security risk, Hostwover may take proportionate protective action.

Depending on the circumstances, this may include:

  • contacting the customer.
  • restricting access.
  • blocking malicious traffic.
  • resetting credentials.
  • isolating a Service.
  • temporarily suspending a Service.
  • requesting remediation; or
  • taking another action permitted under applicable agreements.

Where practical and safe, Hostwover will seek to minimize unnecessary disruption.

60. Availability and Maintenance

Hostwover seeks to maintain reliable Services, but maintenance, security updates, infrastructure failures, provider incidents, attacks, emergencies, or other circumstances may temporarily affect availability.

Hostwover may perform emergency maintenance without normal advance notice when necessary to:

  • remediate a critical vulnerability.
  • contain an attack.
  • protect customer information.
  • protect infrastructure.
  • prevent wider Service disruption; or
  • comply with an urgent legal or provider requirement.

Service-specific availability commitments, if any, are governed by the applicable Service Level Agreement.

61. Security Notifications

Hostwover may contact customers about important security matters, including:

  • suspicious authentication.
  • account compromise.
  • credential resets.
  • vulnerabilities.
  • malicious activity.
  • Service suspension.
  • security maintenance.
  • domain-security issues.
  • Personal Data breaches; or
  • actions required from the customer.

Security communications may be considered essential Service communications and may not be subject to marketing opt-out preferences.

62. Law Enforcement and Regulatory Cooperation

Hostwover may cooperate with lawful requests from competent authorities where required by applicable law.

Security personnel should not disclose customer information solely because an individual claims to represent a government or law-enforcement authority.

Requests should be appropriately verified and handled according to applicable legal and internal procedures.

63. Confidentiality of Security Information

Some Hostwover security information must remain confidential.

Hostwover does not generally publish information such as:

  • private network architecture.
  • firewall rules.
  • internal IP addressing.
  • administrative endpoints.
  • credentials.
  • access tokens.
  • private keys.
  • vulnerability details before remediation.
  • internal monitoring thresholds.
  • fraud-detection logic.
  • security investigation methods.
  • incident evidence.
  • detailed provider configurations; or
  • information that could reasonably facilitate an attack.

The absence of such information from this public Policy does not mean that the applicable security control does not exist.

64. Security Standards and Certifications

Hostwover may use recognized security standards, frameworks, guidance, and industry practices to inform its security program.

Reference to any external framework, standard, guidance, or security practice does not mean that Hostwover has obtained certification against that standard unless Hostwover expressly states that a current certification has been obtained.

Hostwover does not claim any certification solely through publication of this Information Security Policy.

65. Continuous Improvement

Information security is an ongoing process.

Hostwover may continually improve security by:

  • reviewing incidents.
  • monitoring emerging threats.
  • reviewing vulnerabilities.
  • upgrading infrastructure.
  • updating applications.
  • improving monitoring.
  • reviewing access.
  • strengthening authentication.
  • improving development processes.
  • improving backup and recovery practices.
  • reviewing suppliers.
  • conducting testing.
  • updating internal procedures; and
  • incorporating lessons learned.

Security controls may therefore change without requiring every technical change to be reflected individually in this public Policy.

66. Enforcement

Violations of Hostwover security requirements may result in actions appropriate to the circumstances.

For personnel, this may include:

  • access restriction.
  • removal of privileges.
  • disciplinary action; or
  • termination of authorized access or engagement.

For customers, measures may include those permitted under the Terms of Service, Acceptable Use Policy, Abuse Handling Policy, and applicable Service Agreements.

67. No Guarantee of Absolute Security

Hostwover uses reasonable measures designed to protect systems, Services, and information.

However, no Internet-connected system, software application, network, hosting environment, storage system, authentication mechanism, security control, or data-transmission method can be guaranteed to be completely secure.

Accordingly, Hostwover cannot guarantee that unauthorized access, compromise, attack, data loss, vulnerability, or Service disruption will never occur.

This limitation does not reduce any mandatory security obligation imposed on Hostwover by applicable law.

68. Policy Review

Hostwover may periodically review this Information Security Policy to reflect:

  • changes to our Services.
  • changes to infrastructure.
  • changes to technology.
  • security improvements.
  • new threats.
  • regulatory changes.
  • lessons from incidents; and
  • changes to our security practices.

69. Changes to This Policy

Hostwover may update this Policy from time to time.

When the Policy is updated, the Last Updated date will be changed.

Material changes may also be communicated through additional appropriate channels where necessary.

70. Related Hostwover Policies

This Information Security Policy should be read together with applicable Hostwover legal documents, including:

  • Terms of Service.
  • Privacy Policy.
  • Privacy / Data Protection Policy.
  • Acceptable Use Policy.
  • Acceptable Use Agreement.
  • Abuse Handling Policy.
  • Responsible Disclosure Policy.
  • Service Level Agreement.
  • Customer Service Policy; and
  • applicable Service Agreements.

If a conflict exists between this Policy and a mandatory requirement of applicable law, the mandatory legal requirement will prevail to the extent of the conflict.

71. Contact Hostwover

For security-related questions or reports:

Hostwover

Website: hostwover.com

Email: [email protected]

For suspected vulnerabilities, use the subject:

Security Report

For account-specific security incidents, include the relevant account or Service identifier where appropriate.

Never send Hostwover:

  • your account password.
  • private SSH keys.
  • complete API secrets.
  • database passwords.
  • payment-card CVV.
  • recovery codes; or
  • other credentials capable of granting access to your systems.

Hostwover may establish and publish a dedicated security email address for security and vulnerability reports.

72. Final Statement

Protecting our customers, infrastructure, and Services is a continuing responsibility.

Hostwover seeks to combine secure technology, appropriate operational controls, responsible personnel practices, customer awareness, monitoring, incident response, and continuous improvement to maintain a secure environment for the Services we provide.