Security is not a feature. It is a foundation.
From the data centre to your browser session, every layer of Airfree Clouds is engineered to protect your domains, email, and workspace. This page sets out our security practices today and the standards we are working toward.
Compliance roadmap
Building to recognised standards
We are aligning our security programme to internationally recognised standards and working toward independent certification. GDPR obligations are addressed today; ISO 27001 and SOC 2 Type II are in progress.
Information Security Management
We are building our information security management system (ISMS) to align with ISO/IEC 27001:2022 — the international benchmark for information security management — and working toward independent certification.
What this means for you
Your data is protected by systematically managed controls that we are aligning to an internationally recognised standard as we pursue certification.
Service Organisation Controls
We are preparing our security, availability, processing integrity, confidentiality, and privacy controls for a SOC 2 Type II examination over a rolling observation window.
What this means for you
Once complete, a SOC 2 Type II report will provide independent evidence that our controls operate effectively over an extended period.
EU/UK General Data Protection Regulation
We act as both a Data Controller and Data Processor under GDPR. We maintain records of processing activities, conduct DPIAs for high-risk processing, and support all data-subject rights requests within 30 days.
What this means for you
EU and UK customers can exercise their rights to access, correction, erasure, and portability with a single support ticket.
NIST Cybersecurity Framework Aligned
Our security programme is mapped to the NIST CSF 2.0 Identify, Protect, Detect, Respond, and Recover functions, providing a structured, risk-based approach to cyber risk management.
What this means for you
A mature, internationally recognised risk framework governs how we prioritise and remediate threats — not ad-hoc reaction.
Infrastructure
Built on hardened foundations
Physical security, network architecture, and platform resilience designed so your services keep running — even under attack.
Enterprise-grade Data Centres
Production infrastructure is designed to run in enterprise-grade, access-controlled colocation facilities with power and cooling redundancy and physical access controls. Customer data is not processed in hyperscaler shared-tenancy regions without explicit consent.
Network Isolation
Production, staging, and management networks are separated at layer 3 with strict ACLs. East-west traffic between services is zero-trust authenticated via mutual TLS. No service has unrestricted egress to the internet.
BGP Anycast DDoS Mitigation
Our DNS and authoritative name-server infrastructure is designed to distribute across multiple BGP anycast PoPs so volumetric attacks are absorbed at the network edge — traffic is scrubbed before it reaches application layers.
Web Application Firewall
All customer-facing endpoints sit behind a tuned WAF with OWASP CRS rules, rate limiting, geo-fencing, and bot-management. Rules are updated within 24 hours of new CVEs affecting our stack.
Network Operations & Monitoring
Continuous platform-health and security monitoring with on-call incident response. Our target is to acknowledge a P1 security incident within 15 minutes.
Application Security
Secure by design, verified by practice
We bake security into every stage of the software development lifecycle — from code review to independent penetration testing.
OWASP Top 10 Mitigations
Every release is reviewed against OWASP Top 10. Developers receive mandatory secure-coding training annually. Code review checklists include injection, broken auth, SSRF, and misconfiguration checks.
Dependency Scanning
Dependabot and a secondary SCA tool run on every pull request. Critical CVEs in runtime dependencies block merges automatically. We target patch deployment within 24 hours for CVSS 9.0+ vulnerabilities.
Independent Penetration Testing
We are establishing an annual independent penetration-testing programme — full-scope tests of our public attack surface by CREST-certified testers, with grey-box application testing included. Findings are remediated on a risk-tiered schedule (P1 within 48 hours).
Coordinated Vulnerability Disclosure
Security researchers can report vulnerabilities to security@airfreeclouds.com; we aim to acknowledge valid reports within 5 business days. We are establishing a private bug-bounty programme with rewards scaled to CVSS severity.
Account Security
You are in control of your account
Modern authentication methods and full session visibility give you — not just us — control over who can access your account.
TOTP Two-Factor Authentication
Time-based one-time passwords are supported on all accounts via any RFC 6238-compatible authenticator. Backup codes are generated at enrolment and can be regenerated at any time from the security settings page.
WebAuthn / Passkeys
Passwordless login and step-up authentication using WebAuthn Level 2 passkeys. Credentials are bound to your device and origin — phishing-resistant by design.
Hardware Security Key Support
FIDO2-certified hardware keys (YubiKey, Titan, and compatible devices) are supported as a primary or secondary factor. Enterprise accounts can enforce hardware-key-only login via policy.
Session Management
Every active session is visible in your account dashboard with device, browser, IP, and last-active timestamp. Sessions can be individually revoked or all non-current sessions terminated with one click.
Login Anomaly Alerts
Logins from new devices, unusual locations, or outside normal access hours trigger an email alert with a one-click block link. Persistent anomalies escalate to account lockout pending manual verification.
Data Security
Your data, encrypted end to end
From storage to transit to key management, every piece of your data is cryptographically protected — and we can prove it.
AES-256 Encryption at Rest
All customer data — mailboxes, files, DNS records, domain data — is encrypted at rest using AES-256-GCM. Encryption keys are never co-located with the data they protect.
TLS 1.3 in Transit
All data in transit is protected by TLS 1.3 or higher. TLS 1.0 and 1.1 are permanently disabled across all endpoints. HSTS with a 1-year max-age and preload submission is enforced on all customer-facing domains.
HSM Key Management
Master encryption keys are held in hardware security modules (HSMs), and we are targeting FIPS 140-2 validated HSMs. Key rotation is automated on a 90-day cycle for symmetric keys and annually for asymmetric keys.
No Plaintext Credential Storage
User passwords are hashed with Argon2id (memory-hard, side-channel-resistant). API tokens are stored as salted SHA-256 hashes. No plaintext credentials, tokens, or keys are ever written to disk or logs.
Vulnerability Disclosure
Found something? Tell us.
We take every security report seriously and commit to transparent, coordinated disclosure.
security@airfreeclouds.com
Please do not disclose potential vulnerabilities publicly before we have had the opportunity to investigate and remediate. We will credit researchers who follow responsible disclosure in our public advisory notices.
Ready to move to a platform you can trust?
Register your domain today. Free WHOIS privacy included. No data reselling. Cancel any time.