Security Policy
Applies to: host.yt, the customer panel, billing portal, support channels, and services provided by Marko Omelyash VARSOFIA.
Plain-language summary
This summary is for convenience only. The full provisions below form the legally relevant text.
1. Shared responsibility
Security is shared. Hostyt is responsible for protecting the infrastructure we control. You are responsible for your accounts, credentials, website code, application configuration, content, users, devices, and data.
2. Our measures
We use security measures designed to protect the platform, including access controls, monitoring, network controls, vulnerability management, logging, backup processes, incident response, and supplier management.
3. Customer requirements
- Use strong unique passwords and enable two-factor authentication where available.
- Keep CMS, plugins, themes, scripts, operating systems, and packages updated.
- Remove unused accounts, plugins, themes, keys, and software.
- Use least privilege for staff, contractors, API keys, and database users.
- Protect admin panels, SSH, FTP/SFTP, email accounts, and control panel access.
- Maintain independent backups and test restores.
4. Security incidents
If we detect a security issue, we may take urgent action to protect the platform, including disabling files, changing permissions, resetting credentials, suspending services, blocking traffic, or isolating affected workloads.
5. Vulnerability reports
Security researchers should follow the Responsible Disclosure Policy and contact abuse@host.yt or legal@host.yt.
6. Regulated data
Unless expressly agreed in writing, the Services are not designed for highly regulated data or workloads requiring specific certifications such as healthcare, classified, cardholder, banking, or critical-infrastructure environments.
Updates
We may update this document from time to time. The version published on host.yt is the current version. If a change materially affects active paid services, we may notify affected customers by email, account notice, ticket, or another reasonable channel.