Security Overview
This page summarises how we approach platform security for iHoster24. It is an overview for customers — not a SOC 2 / ISO certificate, penetration-test report, or guarantee against all threats.
1. Scope
These practices apply to the iHoster24 control plane (website, Client Area) and the hosting platforms we operate for shared hosting, business hosting, VPS, and reseller services. Your application code, CMS plugins, mail content, and end-user devices remain your responsibility.
2. Platform measures
Depending on product and plan, measures typically include: TLS for public websites and Client Area sessions; logical isolation between customer accounts on shared platforms; host hardening and vulnerability patching on a recurring schedule; restricted administrative access; and backups as described in the Backup Policy.
3. Access control
Staff access to production systems is limited to roles that need it. Customers should enable strong passwords and two-factor authentication (2FA) where available in the Client Area, and avoid sharing credentials in chat or email.
4. Network and perimeter
We apply firewalling and abuse controls consistent with our Acceptable Use Policy. We may rate-limit, filter, or temporarily block traffic that threatens platform stability or other customers.
5. Data handling
How we process personal data is described in the Privacy Policy and, where we act as processor for customer-hosted personal data, in the DPA. Payment card data is handled by payment providers listed under Subprocessors — we do not store full card PANs on our systems.
6. Monitoring and response
We monitor service health and investigate abuse, malware, and compromise indicators. Response may include notifying the account holder, requesting remediation, isolating a service, or suspending accounts under the Terms and AUP.
7. Customer responsibilities
- Keep CMS, plugins, themes, frameworks, and server-side software you manage patched.
- Use unique passwords and 2FA; rotate credentials after staff changes.
- Do not host malware, phishing, or other AUP-prohibited content.
- Maintain your own application-level backups for critical data (see Backup Policy).
- Review file permissions and disable unused services on VPS products you administer.
8. Reporting a security issue
Report suspected platform compromises, vulnerability disclosures affecting iHoster24 infrastructure, or abuse to abuse@dioartis.com or via a Client Area ticket. Include URLs/IPs, timestamps (UTC), and evidence where possible. Do not publicly disclose unfixed vulnerabilities without coordinating with us first.
9. Updates
We may update this overview as practices evolve. Material changes will be reflected in the document information block above.