Your Cart

Services & Domains

Estimated total

$0.00

Taxes

Included

Proceed to checkout

Secure payment by Dynetwork

Dark Mode
7-Layer Security

Secure
Infrastructure

A holistic approach to security, from the data center to the application, protecting your data, your services and the trust your customers place in you.

Our approach

Our holistic approach to security

Keeping security risks to an absolute minimum calls for a holistic approach. Our security processes start from a clear definition of the threats facing our systems.

Security objectives

Confidentiality

Information held within our infrastructure and systems is accessible only to authorized users.

Integrity

The data and information in our infrastructure cannot be altered by any unauthorized user.

Data protection

The data stored on our systems cannot be damaged, deleted or destroyed.

Identification and authentication

Ensures that every user of the system is genuinely who they claim to be, eliminating the risk of identity spoofing.

Network service protection

Ensures that network equipment is protected against malicious hacking attempts and attacks that threaten availability.

Our model

Our holistic security model

Our platform and security processes rely on multiple layers of protection — security systems and hardware combined with rigorous procedures, best practices and audit processes — to deliver unmatched security across every service we provide. The platform addresses security at 7 distinct levels.

01
Level 1

Data Center Security

Our partnerships with data centers around the world are the result of a thorough due diligence process, in which security and stability rank among the most important factors. Every data center is equipped with surveillance cameras, biometric locks, authorization-based access policies, restricted access, security personnel and comparable industry-standard security equipment, processes and operations.

What sets us apart is that our due diligence process also measures how proactive a data center is about security. We assess this by reviewing its track record, customer case studies and the time it invests in security research and study.

02
Level 2

Network Security

Our global infrastructure deployments include DDoS mitigation devices, intrusion detection systems and firewalls, both at the edge and at the rack level. Our deployments have withstood frequent hacking attempts and DDoS attacks (sometimes as many as three in a single day) with no degradation in service.

Firewall protection

Our firewall protection runs 24/7: it secures the perimeter and provides the strongest possible first line of defense. It uses advanced, highly adaptive inspection technology to protect your data, website, email and web applications by blocking any unauthorized network access. It maintains controlled connectivity between the servers that store your data and the internet, enforcing security policies designed by experts.

Network intrusion detection system

Our intrusion detection, prevention and vulnerability management system delivers fast, accurate and comprehensive protection against targeted attacks, traffic anomalies, "unknown" worms, spyware/adware, network viruses, malicious applications and other zero-day exploits. It relies on state-of-the-art, high-performance network processors that run thousands of checks on each packet flow simultaneously, with no noticeable increase in latency. As they pass through our systems, packets are fully inspected to determine whether they are legitimate or harmful. This real-time protection is the most effective mechanism for stopping attacks before they reach their targets.

DDoS attack protection

Denial of service is today the leading source of financial loss from cybercrime. The goal of a denial-of-service attack is to disrupt your business by taking down your website, email or web applications. Attackers do this by targeting the servers or network hosting these services and overwhelming key resources such as bandwidth, CPU and memory. Common motives include extortion, notoriety, political statements or unfair competition. Virtually any organization connected to the internet is vulnerable to these attacks, and the impact can be enormous: lost revenue, dissatisfied customers, reduced productivity — not to mention potentially record-breaking bandwidth overage bills.

Our DDoS protection delivers unmatched defense for your internet-facing infrastructure (websites, email and business-critical web applications) through cutting-edge technology that triggers automatically the moment an attack begins. The mitigation appliance filters out nearly all fraudulent traffic while letting legitimate traffic through to the greatest extent possible. These systems have transparently protected multiple websites from major service outages caused by simultaneous attacks exceeding 300 Mbps, allowing organizations to stay focused on their business.

03
Level 3

Host Security

Host-based intrusion detection system (HIDS)

As tools capable of bypassing perimeter defenses such as port-blocking firewalls have emerged, deploying a host-based intrusion detection system (HIDS) — focused on monitoring and analyzing the internals of a computing system — has become essential for businesses. Our HIDS helps detect and pinpoint changes to the system and its configuration files — whether accidental, the result of malicious tampering or an external intrusion — using heuristic scanners, host logs and system activity monitoring. Detecting changes early reduces the risk of potential damage and shortens troubleshooting and recovery times, lowering overall impact while improving system security and availability.

Hardware standardization

We have standardized on hardware vendors recognized for their high security standards and quality support. Most of our infrastructure and data center partners use equipment from Cisco, Juniper, HP, Dell and similar vendors.

04
Level 4

Software Security

Our applications run on a wide range of server systems and software. Operating systems include various distributions of Linux, BSD and Windows. Server software includes different versions of Apache, IIS, Resin, Tomcat, Postgres, MySQL, MSSQL, Qmail, Sendmail, Proftpd and more. We keep this diverse software portfolio secure by following a process-driven approach.

Rapid deployment of security updates and patches

All servers are enrolled in automatic updates so they always run the latest security patch and any newly discovered vulnerability is addressed as quickly as possible. The majority of intrusions stem from exploiting known vulnerabilities, configuration errors or virus attacks for which countermeasures ALREADY exist. According to CERT, systems and networks are affected by these events because they did "not consistently" deploy the patches that were available. We have put in place consistent, repeatable processes together with a reliable audit and reporting framework that keeps all of our systems fully up to date.

Periodic security scans

Frequent checks are carried out using enterprise-grade security software to determine whether any servers expose known vulnerabilities. Servers are scanned against the most comprehensive and up-to-date vulnerability databases available. This lets us protect our servers proactively and ensure business continuity by identifying weaknesses before an attack can occur.

Testing before upgrades

Software vendors release upgrades frequently. Each vendor follows its own testing procedures but cannot test for interoperability issues across different software. For example, a new database release may be tested by its vendor, yet the impact of deploying it on a production system running a mix of FTP, mail and web server software cannot be determined directly. Our system administration team documents the impact analysis for each upgrade, and when one is deemed high risk it is first beta-tested in our labs before any production rollout.

05
Level 5

Application Security

All of the application software used on the platform is developed in-house. We do not outsource development. Every third-party product or component goes through comprehensive training and testing procedures in which all of its elements are broken down and knowledge of its architecture and implementation is transferred to our team. This gives us full command of every variable tied to a given product. All applications are built using our proprietary product engineering process, which takes a proactive approach to security.

Each application is broken down into distinct components: the user interface, the core API, the back-end database and so on. Every abstraction layer has its own security controls, independent of those performed by any layer above it. All sensitive data is stored in encrypted form. Our engineering and development practices guarantee the highest level of security across all application software.

06
Level 6

Personnel Security

The weakest link in the security chain will always be the people you place your trust in: staff, development teams, contractors — in short, anyone with privileged access to your system. Our holistic approach is designed to minimize the security risk posed by the "human factor". Information is disclosed strictly on a "need-to-know" basis. Authorization expires as soon as the need ends. Personnel are specifically trained in security measures and in how critical it is to follow them.

Every employee with administrator privileges on any of our servers undergoes a thorough background check. Companies that skip this step put all of their customers' sensitive and important data at risk: no matter how much is invested in top-tier security solutions, a single bad hire — with the right level of access — can cause more damage than any external attack.

07
Level 7

Security Audit Process

In a large-scale deployment of servers spread across the globe, audit processes are needed to ensure process replication and discipline. Are all servers patched on a regular basis? Are the backup scripts running at all times? Are off-site backups rotated as planned? Are proper reference checks carried out on all staff? Does the security equipment raise alerts in a timely manner?

These questions, and many more, are checked regularly as part of an out-of-band process that includes investigations, surveys, ethical hacking attempts, interviews and more. Our audit mechanisms alert us to the slightest gap in our security processes before it can be discovered by outside users.