Skip to main content
Security

Security is not a feature. It is a foundation.

From the data centre to your browser session, every layer of Airfree Clouds is engineered to protect your domains, email, and workspace. This page sets out our security practices today and the standards we are working toward.

Compliance roadmap

Building to recognised standards

We are aligning our security programme to internationally recognised standards and working toward independent certification. GDPR obligations are addressed today; ISO 27001 and SOC 2 Type II are in progress.

ISO 27001:2022 (in progress)

Information Security Management

We are building our information security management system (ISMS) to align with ISO/IEC 27001:2022 — the international benchmark for information security management — and working toward independent certification.

What this means for you

Your data is protected by systematically managed controls that we are aligning to an internationally recognised standard as we pursue certification.

SOC 2 Type II (planned)

Service Organisation Controls

We are preparing our security, availability, processing integrity, confidentiality, and privacy controls for a SOC 2 Type II examination over a rolling observation window.

What this means for you

Once complete, a SOC 2 Type II report will provide independent evidence that our controls operate effectively over an extended period.

GDPR

EU/UK General Data Protection Regulation

We act as both a Data Controller and Data Processor under GDPR. We maintain records of processing activities, conduct DPIAs for high-risk processing, and support all data-subject rights requests within 30 days.

What this means for you

EU and UK customers can exercise their rights to access, correction, erasure, and portability with a single support ticket.

NIST CSF

NIST Cybersecurity Framework Aligned

Our security programme is mapped to the NIST CSF 2.0 Identify, Protect, Detect, Respond, and Recover functions, providing a structured, risk-based approach to cyber risk management.

What this means for you

A mature, internationally recognised risk framework governs how we prioritise and remediate threats — not ad-hoc reaction.

Infrastructure

Built on hardened foundations

Physical security, network architecture, and platform resilience designed so your services keep running — even under attack.

Enterprise-grade Data Centres

Production infrastructure is designed to run in enterprise-grade, access-controlled colocation facilities with power and cooling redundancy and physical access controls. Customer data is not processed in hyperscaler shared-tenancy regions without explicit consent.

Network Isolation

Production, staging, and management networks are separated at layer 3 with strict ACLs. East-west traffic between services is zero-trust authenticated via mutual TLS. No service has unrestricted egress to the internet.

BGP Anycast DDoS Mitigation

Our DNS and authoritative name-server infrastructure is designed to distribute across multiple BGP anycast PoPs so volumetric attacks are absorbed at the network edge — traffic is scrubbed before it reaches application layers.

Web Application Firewall

All customer-facing endpoints sit behind a tuned WAF with OWASP CRS rules, rate limiting, geo-fencing, and bot-management. Rules are updated within 24 hours of new CVEs affecting our stack.

Network Operations & Monitoring

Continuous platform-health and security monitoring with on-call incident response. Our target is to acknowledge a P1 security incident within 15 minutes.

Application Security

Secure by design, verified by practice

We bake security into every stage of the software development lifecycle — from code review to independent penetration testing.

OWASP Top 10 Mitigations

Every release is reviewed against OWASP Top 10. Developers receive mandatory secure-coding training annually. Code review checklists include injection, broken auth, SSRF, and misconfiguration checks.

Dependency Scanning

Dependabot and a secondary SCA tool run on every pull request. Critical CVEs in runtime dependencies block merges automatically. We target patch deployment within 24 hours for CVSS 9.0+ vulnerabilities.

Independent Penetration Testing

We are establishing an annual independent penetration-testing programme — full-scope tests of our public attack surface by CREST-certified testers, with grey-box application testing included. Findings are remediated on a risk-tiered schedule (P1 within 48 hours).

Coordinated Vulnerability Disclosure

Security researchers can report vulnerabilities to security@airfreeclouds.com; we aim to acknowledge valid reports within 5 business days. We are establishing a private bug-bounty programme with rewards scaled to CVSS severity.

Account Security

You are in control of your account

Modern authentication methods and full session visibility give you — not just us — control over who can access your account.

TOTP Two-Factor Authentication

Time-based one-time passwords are supported on all accounts via any RFC 6238-compatible authenticator. Backup codes are generated at enrolment and can be regenerated at any time from the security settings page.

WebAuthn / Passkeys

Passwordless login and step-up authentication using WebAuthn Level 2 passkeys. Credentials are bound to your device and origin — phishing-resistant by design.

Hardware Security Key Support

FIDO2-certified hardware keys (YubiKey, Titan, and compatible devices) are supported as a primary or secondary factor. Enterprise accounts can enforce hardware-key-only login via policy.

Session Management

Every active session is visible in your account dashboard with device, browser, IP, and last-active timestamp. Sessions can be individually revoked or all non-current sessions terminated with one click.

Login Anomaly Alerts

Logins from new devices, unusual locations, or outside normal access hours trigger an email alert with a one-click block link. Persistent anomalies escalate to account lockout pending manual verification.

Data Security

Your data, encrypted end to end

From storage to transit to key management, every piece of your data is cryptographically protected — and we can prove it.

AES-256 Encryption at Rest

All customer data — mailboxes, files, DNS records, domain data — is encrypted at rest using AES-256-GCM. Encryption keys are never co-located with the data they protect.

TLS 1.3 in Transit

All data in transit is protected by TLS 1.3 or higher. TLS 1.0 and 1.1 are permanently disabled across all endpoints. HSTS with a 1-year max-age and preload submission is enforced on all customer-facing domains.

HSM Key Management

Master encryption keys are held in hardware security modules (HSMs), and we are targeting FIPS 140-2 validated HSMs. Key rotation is automated on a 90-day cycle for symmetric keys and annually for asymmetric keys.

No Plaintext Credential Storage

User passwords are hashed with Argon2id (memory-hard, side-channel-resistant). API tokens are stored as salted SHA-256 hashes. No plaintext credentials, tokens, or keys are ever written to disk or logs.

Vulnerability Disclosure

Found something? Tell us.

We take every security report seriously and commit to transparent, coordinated disclosure.

security@airfreeclouds.com

Initial response SLA5 business days
Remediation target (P1)48 hours from confirmation
Full disclosure timeline90 days (coordinated)
Disclosure policyCoordinated — we notify affected users before public disclosure
PGP keyAvailable on request via email
Bug bountyPrivate programme — request invitation by email

Please do not disclose potential vulnerabilities publicly before we have had the opportunity to investigate and remediate. We will credit researchers who follow responsible disclosure in our public advisory notices.

Privacy-first platform

Ready to move to a platform you can trust?

Register your domain today. Free WHOIS privacy included. No data reselling. Cancel any time.