Security information

Clear security responsibilities

AIHOSTON protects its application and ordering systems while customers retain responsibility for administering their server workloads. This page avoids certification, mitigation-capacity, and compliance claims that have not been independently published and verified.

Security practices and responsibilities

Account protection

Use a unique password and protect the email account associated with your AIHOSTON login. Never share server or account credentials through public channels.

Server administration

Customers are responsible for securing the operating system and applications they deploy, including updates, firewall rules, access control, and backups unless an order explicitly states otherwise.

Payments and sensitive data

Payment amounts are validated server-side against order records. Credentials, private keys, passwords, and payment details must not be sent to analytics.

Access boundaries

Customer and administrative actions require server-side authentication and authorization. Report any suspected cross-account access immediately.

Responsible disclosure

If you believe you found a vulnerability, provide a clear description, affected URL or component, and safe reproduction steps. Do not access other customers' data, disrupt service, or publish sensitive details before AIHOSTON can investigate.

Report a security issue

Before deploying a server

  • Apply operating-system and application updates
  • Restrict remote access and exposed ports
  • Use SSH keys or strong unique credentials
  • Maintain a tested, independent backup
  • Monitor logs and remove unused accounts
Security and Responsible Disclosure | AIHOSTON