Security
How WebHost24 keeps customer data + workloads safe: from the network edge down to the application pod. Security inquiries: security@webhost24.in.
DDoS protection at the CDN edge
Anycast L3/L4 mitigation at every PoP. The CDN absorbs attacks before they reach Palitana.
Per-app container isolation
Each customer runs in a dedicated Kubernetes pod with resource limits + AppArmor profiles + seccomp defaults. No shared namespaces.
Encrypted backups
Daily snapshots land on the S3 Standard tier with AES-256 server-side encryption + at-rest encryption on the underlying disk array.
TLS 1.3 + HSTS everywhere
All customer endpoints (web + API + control panel) terminate TLS 1.3 only. HSTS preload shipped on webhost24.in.
SOC 2 (Type II) audited
Annual third-party audit covers availability + confidentiality + processing-integrity. Report on request under NDA.
Quarterly penetration testing
Independent third-party tests every quarter. Findings triaged within 14 days; critical issues patched within 48 hours.
Background-checked staff
All engineering + ops hires are background-checked before onboarding. Production access requires 2-person integrity for sensitive operations.
DPDPA + GDPR-aligned data handling
Customer data stays in India. We honour data-subject access requests within 30 days. See the [DPA](/dpa) for the formal processor-controller relationship.
Report a vulnerability: security@webhost24.in. We acknowledge within 1 Indian business day and triage critical issues within 48 hours.