Security Policy
How ESM approaches infrastructure security, managed and unmanaged responsibility, access control, monitoring, incident response, backups, DDoS, and customer security obligations.
Plain-English note: These public terms are written to explain ESM's operating and commercial expectations clearly. Service-specific order forms, invoices, statements of work, signed agreements, and rights that cannot legally be excluded may also apply.
Security Policy
This Security Policy describes the general security approach used by eLite Server Management for systems and infrastructure under our operational control and explains the shared responsibilities that apply to customers using hosting, VPS, dedicated servers, IPv4 resources, management, migration, monitoring, backup, and security services.
Security is an ongoing operational process, not an absolute guarantee. This Policy does not represent a certification or promise that any environment is immune from compromise, outages, software vulnerabilities, malicious traffic, or human error.
1. Purpose
- Explain ESM's general security objectives and operational practices.
- Define the shared-responsibility model between ESM and customers.
- Describe how security monitoring, incident handling, and protective actions may operate.
- Clarify the difference between managed and unmanaged security responsibility.
2. Scope
This Policy applies to ESM-controlled websites, billing/support systems, hosting platforms, network resources, managed server components, monitoring systems, and infrastructure ESM directly administers. It does not automatically extend to customer-developed applications, customer code, third-party plugins/themes, unmanaged operating systems, customer devices, external services, or systems outside ESM's control.
3. Security Principles
ESM's security approach is guided by confidentiality, integrity, availability, least privilege, operational visibility, defence in depth where practical, timely remediation, and continuous improvement. Specific tooling and internal architecture may change as threats, technology, vendors, and services evolve.
4. Shared Responsibility Model
| Area | ESM generally responsible for | Customer generally responsible for |
|---|---|---|
| Platform / physical infrastructure | Components directly operated or contracted by ESM | Workload requirements and appropriate service selection |
| Managed OS / services | Items expressly included in the management plan | Unsupported software and out-of-scope applications |
| Applications / websites | Hosting platform controls where applicable | Code, CMS, plugins, themes, users, content, application security |
| Credentials | Internal administrative access controls | Customer passwords, SSH keys, MFA, API keys, delegated users |
| Backups | Purchased backup service scope | Independent copies and recovery requirements |
5. Security Governance
ESM maintains operational procedures intended to support secure administration, access management, service changes, monitoring, incident handling, abuse response, infrastructure maintenance, and supplier coordination. Exact internal security tools, detection rules, credentials, network diagrams, and defensive configurations are confidential.
6. Physical & Data-Center Security
Physical servers may be located in third-party data centers selected for appropriate operational capabilities. Physical security controls can include restricted facility access, surveillance, access authorization, environmental controls, redundant power, and on-site operational procedures depending on the facility and service.
7. Network Security
ESM and its network/data-center providers may use routing controls, firewalling, filtering, segmentation, access restrictions, monitoring, upstream carrier controls, and other network safeguards appropriate to the service. Network architecture may be changed without public notice when necessary for security or reliability.
8. DDoS, Malicious Traffic & Abuse Defense
DDoS mitigation and network filtering reduce risk but cannot guarantee protection from every attack. ESM may rate-limit, filter, reroute, blackhole, null-route, isolate, or temporarily restrict traffic when needed to protect networks, upstream providers, or other customers.
9. Server & Platform Security
For systems ESM manages, security measures may include baseline hardening, service configuration, firewall controls, administrative access restrictions, software updates, monitoring, and review of security events according to the purchased service. Unmanaged servers remain principally under the customer's administrative control.
10. Patching & Vulnerability Management
ESM applies or recommends security updates for supported components within applicable managed scope. Patch timing may consider severity, service compatibility, maintenance impact, vendor guidance, and operational risk. Customers remain responsible for unsupported software, custom applications, and components outside managed scope.
11. Access Control & Least Privilege
Administrative access to ESM-controlled systems is intended to be limited to authorized personnel or service providers with a legitimate operational need. Access may be logged or reviewed where appropriate. Customers should likewise limit privileged access within their environments.
12. Credential & Authentication Security
Customers should use unique passwords, MFA where available, protected SSH keys, restricted API keys, and prompt credential rotation after personnel changes or suspected compromise. Credentials should not be shared through insecure channels. ESM may require credential changes when compromise is suspected.
13. Encryption & Secure Transport
ESM generally uses HTTPS/TLS for public websites, authenticated portals, and supported communications where technically appropriate. Customers are responsible for implementing encryption within their own applications, databases, mail workflows, backups, and custom services where their risk profile requires it.
14. Security Monitoring & Logging
Operational monitoring may include service health, resource utilization, authentication events, administrative activity, network events, abuse indicators, errors, availability, and capacity. Logs may be used for troubleshooting, security, abuse prevention, legal response, service improvement, and incident investigation in accordance with applicable privacy obligations.
15. Malware, Compromise & Blacklisting
When malware, compromise, unauthorized mail, or suspicious activity is identified, ESM may isolate affected services, block traffic, suspend mail, request credential changes, or recommend a malware-cleanup/security service. Customers remain responsible for remediation outside their purchased management/security scope.
16. Security Incident Response
ESM may investigate suspected incidents by collecting relevant logs, preserving evidence, limiting access, isolating systems, engaging data-center or upstream providers, restoring supported services, rotating credentials, and notifying affected parties where appropriate or legally required.
17. Backup & Recovery Security
Backup security depends on the purchased service and storage location. Customers should maintain independent backups and periodically verify restore readiness. ESM does not represent that every backup can be restored after corruption, compromise, ransomware, accidental deletion, supplier failure, or expiration of retention.
18. Managed vs. Unmanaged Environments
Managed services shift responsibility only for the tasks expressly included in the plan. Unmanaged VPS and Dedicated Servers generally leave operating-system, application, firewall, user, software-update, and backup responsibility with the customer. Purchasing infrastructure alone does not create a managed-security obligation.
19. Customer Security Responsibilities
- Protect account credentials, MFA devices, SSH keys, API keys, and control-panel access.
- Keep websites, CMS installations, plugins, themes, custom code, applications, and databases secure.
- Maintain appropriate backups and tested recovery procedures.
- Remove or remediate malware, exposed services, weak credentials, and compromised accounts.
- Notify ESM promptly of suspected compromise or abuse affecting ESM infrastructure.
- Cooperate with reasonable security and abuse-remediation requests.
20. Third-Party Providers
ESM depends on data centers, carriers, software vendors, security providers, control-panel vendors, cloud providers, domain registrars, and other third parties. Their independent security practices, incidents, and outages are outside ESM's direct control. ESM may replace suppliers or technologies where operationally appropriate.
21. Vulnerability & Security Reporting
If you believe you have identified a security issue affecting ESM, contact us with sufficient technical detail to reproduce and assess the issue. Do not exploit vulnerabilities beyond what is reasonably necessary to demonstrate the issue, access other customers' data, disrupt services, conduct destructive testing, or publicly disclose sensitive details before ESM has had a reasonable opportunity to investigate.
22. Protective Suspension & Emergency Action
ESM may temporarily suspend, isolate, null-route, disable mail, block ports, restrict credentials, or otherwise limit a service without prior notice where necessary to contain an active compromise, protect IP reputation, stop abuse, comply with provider requirements, or reduce immediate risk to networks or third parties.
23. Security Limitations
No security program can eliminate all risk. ESM does not guarantee that services will be free from vulnerabilities, intrusion, data loss, malware, DDoS, credential theft, third-party compromise, or zero-day vulnerabilities. Security features and management services reduce risk but do not transfer every customer responsibility to ESM.
24. Continuous Improvement & Policy Changes
Security controls, tools, procedures, suppliers, and this Policy may be updated as technology, threats, legal requirements, or ESM services change. The latest public version will be published on this page.
25. Security & Abuse Contact
General security questions may be submitted through our Contact page or Support Center. Reports of spam, phishing, malware, attacks, compromised systems, or other abuse should follow our Acceptable Use & Abuse Policy and include affected IPs/domains, timestamps, logs, and supporting evidence where available.
Need to report a security concern?
Provide affected services, IPs or domains, timestamps, relevant logs, and enough context for our team to investigate safely.
Contact Us Support Channels