Legal
Security Policy
Security Policy
Company details: Legal entity name, company number, registered office, VAT number, and ICO registration (if applicable) are configured by administrators and shown when available. Until configured, treat references to the controller identity as incomplete placeholders — not invented registrations.
1. Overview
Rackstead employs layered controls appropriate to a hosting control plane. This page is a high-level summary — it does not disclose sensitive architecture details, credentials, or internal runbooks.
2. Authentication and access
- Password hashing for credentials accounts
- Optional TOTP 2FA
- Session management via Auth.js
- OAuth providers when configured
- Role-based admin permissions
- API keys with scoped access
3. Credentials
Guest root passwords and similar secrets are handled as sensitive server credentials and are never included in privacy exports. SSH private keys are not accepted for upload. Payment card data is processed by payment providers when configured.
4. Infrastructure isolation
Customer workloads are intended to run as isolated virtual machines on host nodes managed via Rackstead's node agent/control plane. Exact hypervisor and network controls are operational details not published here.
5. Logging and monitoring
Login history, activity logs, audit logs, and fraud alerts support security operations. Admin actions on legal/privacy data are audited.
6. Backups
Backup/snapshot features depend on product configuration and host capabilities. Customers remain responsible for application-level backups.
7. Incidents
Security incidents are tracked in an internal Admin → Security → Incidents workflow, including assessment of personal data involvement and notification decisions (ICO/customers) where required by law.
8. Vulnerability disclosure
Report suspected vulnerabilities via /security/report or the security email in Company Details. Please allow a reasonable time for investigation before public disclosure.