Zero Trust · Encryption · DDoS · Disclosure

SECURITY POLICY

We build trust with enterprise customers through multi-layer security, transparent processes and continuous monitoring.

Our Security Approach

With the Zero Trust model, no user, device or connection is trusted by default.

OwnHost security architecture is based on Zero Trust principles: every access request is verified by identity, device posture and context; least privilege is enforced.

From physical data centers to the application layer, multiple security layers work together with defense in depth.

  • Authentication and multi-factor access (MFA)
  • Micro-segmentation and network isolation
  • Continuous monitoring, logging and threat intelligence
  • Encryption, backup and access auditing

Physical Security

Physical access and facility security controls at Tier III data centers.

CCTV

24/7 CCTV monitoring, recording retention and alarm integration across facilities.

Biometric Access

Fingerprint and multi-factor biometric access control in critical data center zones.

Card Access

Role-based card access systems with visitor logging and access audit trails.

Security Personnel

24/7 on-site security staff and incident response procedures.

Network Security

Multi-layer network protection with firewall, IDS/IPS, DDoS and WAF.

Firewall

Layered firewall rules, segmentation and traffic filtering policies.

IDS

Intrusion Detection System for anomalous traffic and attack signature detection.

IPS

Intrusion Prevention System for active threat blocking and automated response.

DDoS Protection

L3/L4/L7 DDoS filtering and traffic scrubbing with Corero & StormWall.

WAF

Web Application Firewall for OWASP Top 10 and bot/attack protection.

Server Security

Server layer protection through patching, hardening, logging and continuous monitoring.

Updates

Regular security patches, CVE tracking and controlled maintenance windows.

Hardening

Minimum open ports, strong authentication and CIS-based server hardening.

Logging

Centralized log collection, audit trails and security event records.

Monitoring

24/7 infrastructure monitoring, anomaly detection and automated alerting.

Data Security

Technical and administrative controls for data confidentiality, integrity and availability.

Encryption

Encryption in transit (TLS) and at rest; sensitive data protection.

Backup

Encrypted backups, offsite copies and disaster-ready data protection.

Access Controls

Role-based access (RBAC), MFA and least privilege principle.

Vulnerability Disclosure

We support security researchers through our Responsible Disclosure program.

Please report security vulnerabilities in OwnHost infrastructure through Responsible Disclosure. Contact us before public disclosure; our team will assess within a reasonable timeframe.

We offer recognition and coordinated remediation for valid reports. Destructive testing, service disruption or data breach activities are out of scope.

security@ownhost.net

Security Certifications

Our processes aligned with international security and compliance standards.

ISO

ISO 27001

Information Security Management System (ISMS) compliance target and continuous improvement.

PCI

PCI DSS

PCI DSS aligned infrastructure controls and segmentation for payment card data.

SOC

SOC 2

SOC 2 Type II readiness for security, availability and confidentiality controls.

Questions about security?

Contact our sales or security team for enterprise security requirements.

Contact Us