|
We can't make your code secure, but we can offer a secure environment in which to run it. Security is not just about setting up a firewall or IPS. It starts with the physical building security and ends with user education: choosing secure passwords, encrypting all file transfers, etc. In order to gain access to our datacenters, technicians must first request access via a secure intranet prior to arrival. On arrival identification is checked and a proximity access card issued. The access card will only allow the technician to open doors to which they have access. Once access to the colocation room is granted, the individual cabinet containing the equipment must be opened either via a key or an access code. Access logs and 24/7 CCTV are also in place. All of this ensures your hardware is highly secure from tampering or theft. Our host servers run a minimal installation of CentOS 5 Linux with automatic daily updates enabled. These servers provide physical resources for Xen guest instances. Access to the physical servers is via a secure VPN connection only. The Xen virtual machines provide services such as DNS, SNMP, HTTP etc. If you rent a Managed Web Server from us, it will be a Xen guest running on one of our host servers. Each virtual machine is further secured with a firewall, restricting ports that will accept incoming connections to the minimum required for the running applications. We only use secure protocols to access and manage our equipment, and we strongly advise our customers to do the same. Any web based administration programs should force access to be over SSL only. File transfers and shell access should be via SFTP/SSH. We can provide VPN accounts to customers who wish to further restrict external access to sensitive applications, and guidance on configuring the necessary firewall rules. If you wish to discuss any security matters with us please do not hesitate to get in touch.
|