Effective Date: July 7, 2026

Last Updated: July 7, 2026


1. Introduction

At Aira Hosting (“Aira Hosting”, “we”, “our”, or “us”), protecting the confidentiality, integrity, and availability of our hosting platform is one of our highest operational priorities. We implement commercially reasonable administrative, technical, and physical safeguards designed to help protect our infrastructure and the services we provide to customers.

This Security Policy explains our general approach to safeguarding our hosting environment, customer accounts, and supporting systems. It also outlines the respective security responsibilities of both Aira Hosting and our customers.

Security is a shared responsibility. While we maintain and secure the infrastructure under our control, customers are responsible for maintaining the security of the applications, websites, data, credentials, and software they deploy on our platform.

This Security Policy should be read together with our:

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Addendum (where applicable)

If any conflict exists between this Security Policy and our Terms of Service, the Terms of Service shall prevail.

Nothing in this Security Policy creates a contractual guarantee, warranty, certification, or representation that any service is completely secure, uninterrupted, or immune from cyber threats.


2. Purpose

The purpose of this Security Policy is to:

  • Describe the security measures Aira Hosting generally implements to protect its infrastructure.
  • Explain the shared security responsibilities between Aira Hosting and its customers.
  • Provide transparency regarding our operational security practices.
  • Explain customer obligations relating to account and application security.
  • Describe how security incidents are handled.
  • Define limitations of our security responsibilities.

This document is intended for informational purposes only and does not constitute a guarantee of any particular level of security or compliance.


3. Scope

This Security Policy applies to the security of systems, services, and infrastructure operated or managed directly by Aira Hosting, including, where applicable:

  • Shared Web Hosting
  • Virtual Private Servers (VPS)
  • Cloud Hosting Services
  • Dedicated Servers
  • Domain Registration Services
  • DNS Management Services
  • Customer Billing Portal
  • Client Account Dashboard
  • Hosting Control Panels
  • Support Systems
  • Internal Administrative Systems
  • Company Website
  • Application Programming Interfaces (APIs), where provided

The security measures described in this policy apply only to systems under the operational control of Aira Hosting.


Services Not Covered

Unless expressly agreed in writing, this Security Policy does not apply to:

  • Customer-developed software
  • Customer websites
  • Customer databases
  • Customer applications
  • Third-party plugins
  • WordPress themes
  • Custom code
  • Email content
  • Customer backups stored outside our systems
  • External cloud providers
  • Third-party software vendors
  • Third-party payment providers
  • CDN providers
  • DNS providers not operated by Aira Hosting
  • Devices owned by customers
  • Customer local networks

Customers remain solely responsible for securing these assets.


4. Security Principles

Our security program is based on practical industry practices appropriate for the size and nature of our business and focuses on the following core principles:

Confidentiality

We implement reasonable safeguards intended to reduce unauthorized access to systems and information under our control.

Integrity

We work to protect hosted infrastructure from unauthorized modification through access controls, authentication mechanisms, logging, and operational procedures.

Availability

We strive to maintain reliable service availability through infrastructure monitoring, redundancy where appropriate, routine maintenance, and operational planning. However, uninterrupted availability cannot be guaranteed.

Continuous Improvement

Cybersecurity is an evolving field. We regularly review our operational practices and may improve, replace, or modify security controls as technology, threats, legal requirements, or business operations change.


5. Shared Responsibility Model

Security within a hosting environment is a shared responsibility between Aira Hosting and each customer.

Understanding these responsibilities is essential for maintaining a secure hosting environment.

Aira Hosting Responsibilities

Aira Hosting is generally responsible for protecting the infrastructure that we own or directly manage, including:

  • Physical server infrastructure under our control
  • Hosting platform management
  • Network infrastructure
  • Hypervisor security (where applicable)
  • Server operating system maintenance (where managed by us)
  • Security monitoring of our infrastructure
  • Access controls for our internal systems
  • Administrative authentication systems
  • Security updates for platform components under our management
  • Infrastructure-level logging
  • Abuse detection
  • Incident response relating to our systems

These responsibilities apply only to infrastructure operated or managed by Aira Hosting.


Customer Responsibilities

Customers remain fully responsible for securing everything they install, upload, configure, or manage within their hosting accounts.

This includes, but is not limited to:

  • Website security
  • Application security
  • CMS installations
  • WordPress updates
  • Plugin updates
  • Theme updates
  • Database security
  • API keys
  • SSH keys
  • FTP credentials
  • Email account security
  • Password management
  • User account permissions
  • Malware uploaded through customer accounts
  • Custom scripts
  • Source code
  • Data backups
  • Firewall configurations within customer-managed environments
  • Security of remote devices used to access hosting services

Failure to properly secure customer-managed resources may result in unauthorized access, malware infections, data loss, or service interruption, for which Aira Hosting shall not be responsible.


Customer Cooperation

Customers agree to cooperate with Aira Hosting during security investigations by:

  • Responding to security-related communications in a timely manner.
  • Updating compromised credentials when requested.
  • Removing malicious files from their hosting environment.
  • Applying software updates.
  • Taking reasonable corrective actions when security issues are identified.

Failure to cooperate may result in temporary suspension or restriction of services where necessary to protect our infrastructure, other customers, or the public.


6. Security Governance

Aira Hosting maintains internal operational procedures intended to promote the secure management of our hosting platform.

Depending on the nature and size of our operations, these procedures may include:

  • Administrative access controls.
  • Password management practices.
  • Secure system configuration.
  • Change management procedures.
  • Monitoring of production infrastructure.
  • Logging of administrative activities.
  • Security maintenance activities.
  • Periodic review of operational risks.
  • Incident response planning.
  • Abuse management procedures.

As a growing hosting provider, we continuously review and improve our security practices as our services evolve.

The specific technologies, vendors, software, monitoring systems, and security controls used by Aira Hosting are confidential and may be modified, replaced, enhanced, or removed at any time without prior notice for security, operational, or business reasons.

To protect our infrastructure, we do not publicly disclose detailed technical information regarding our internal security architecture, defensive technologies, monitoring capabilities, or operational procedures.

7. Infrastructure Security

Aira Hosting implements commercially reasonable security measures intended to help protect the infrastructure used to provide our hosting services. While no security program can eliminate every risk, we continually evaluate and improve our operational practices as our business grows.

Our infrastructure security measures may include, where applicable:

  • Secure hosting facilities operated by trusted infrastructure providers.
  • Controlled physical access to servers by authorized personnel only.
  • Network segmentation where appropriate.
  • Firewall protection.
  • Administrative access controls.
  • Secure server provisioning procedures.
  • Infrastructure monitoring.
  • Hardware health monitoring.
  • System logging.
  • Redundant power and networking provided by our infrastructure partners, where available.

Because our infrastructure may evolve over time, the specific technologies, vendors, hardware models, software, and security products used are subject to change without notice.

Nothing in this policy should be interpreted as a guarantee that infrastructure failures, hardware defects, or cyberattacks will never occur.


8. Network Security

Protecting our network is an important component of our security program.

Depending on the services provided, Aira Hosting may implement measures such as:

  • Network firewalls.
  • Traffic filtering.
  • Network monitoring.
  • Suspicious traffic detection.
  • IP reputation analysis.
  • Abuse detection.
  • Port access restrictions.
  • Administrative network segregation.
  • Rate limiting where appropriate.
  • Logging of network events.

Certain hosting plans may also benefit from network protections provided by upstream infrastructure providers or data center partners.

Although these controls reduce risk, they cannot completely prevent:

  • Distributed Denial of Service (DDoS) attacks.
  • Internet routing failures.
  • Global network outages.
  • Large-scale cyberattacks.
  • Zero-day exploitation.
  • Third-party network disruptions.

Service degradation or temporary interruptions may occur despite reasonable protective measures.


9. Server Security

Aira Hosting follows reasonable operational practices to help secure servers under our management.

These practices may include:

  • Secure operating system configuration.
  • Timely application of security patches where operationally appropriate.
  • Removal or disabling of unnecessary services.
  • Access restrictions for administrative interfaces.
  • Security logging.
  • Authentication controls.
  • Service monitoring.
  • Resource monitoring.
  • Controlled administrative access.
  • Configuration management.

Servers may be restarted or temporarily taken offline to apply critical security updates, perform maintenance, investigate suspected compromises, or protect the stability of the platform.

Customers acknowledge that emergency maintenance may occur without prior notice when reasonably necessary to maintain platform security.


10. Access Control and Authentication

Access to Aira Hosting systems is restricted based on operational necessity.

Administrative access is generally granted only to authorized personnel who require such access to perform legitimate business functions.

Security measures may include:

  • Unique administrator accounts.
  • Authentication controls.
  • Role-based access principles where appropriate.
  • Password requirements.
  • Session management.
  • Administrative logging.
  • Periodic credential review.
  • Revocation of unnecessary access.

Customers are responsible for protecting access to their own hosting accounts.

Customers should:

  • Choose strong and unique passwords.
  • Keep login credentials confidential.
  • Use multi-factor authentication where available.
  • Regularly review account access.
  • Remove inactive users.
  • Immediately update passwords if compromise is suspected.

Customers are solely responsible for all activity occurring under their account credentials unless otherwise required by applicable law.


11. Data Transmission and Encryption

Aira Hosting seeks to use appropriate encryption technologies to help protect data transmitted through supported services.

Depending on the service involved, protections may include:

  • HTTPS.
  • TLS (Transport Layer Security).
  • Secure administrative interfaces.
  • Encrypted authentication sessions.
  • Secure payment processing connections.
  • Encrypted API communications where applicable.

Certain internal systems may also utilize encryption technologies for specific operational purposes.

However, customers acknowledge that:

  • Encryption standards evolve over time.
  • Internet communications inherently carry security risks.
  • Third-party services may use different security practices.
  • Encryption cannot guarantee absolute confidentiality.

Customers are responsible for implementing encryption within their own applications whenever appropriate.


12. Security Monitoring and Logging

Aira Hosting performs operational monitoring intended to identify abnormal events affecting our infrastructure.

Monitoring activities may include:

  • Infrastructure health monitoring.
  • Resource utilization monitoring.
  • Network event monitoring.
  • Authentication monitoring.
  • Administrative activity logging.
  • Error monitoring.
  • Abuse monitoring.
  • Service availability monitoring.
  • Capacity monitoring.

System logs may be collected for operational, troubleshooting, abuse prevention, security, legal, and compliance purposes.

To protect platform integrity, Aira Hosting reserves the right to review relevant logs when investigating:

  • Security incidents.
  • Service abuse.
  • Malware.
  • Unauthorized access.
  • Network attacks.
  • Violations of our Terms of Service or Acceptable Use Policy.

Logging practices are carried out in accordance with our Privacy Policy and applicable laws.


13. Vulnerability Management and Malware Response

Security Updates

Cybersecurity threats continuously evolve.

Aira Hosting monitors security developments affecting technologies used within our hosting environment and, where appropriate, applies security updates intended to reduce known risks.

The timing of updates depends on several factors, including:

  • Severity of the vulnerability.
  • Operational impact.
  • Vendor guidance.
  • Compatibility testing.
  • Service stability considerations.

Emergency updates may be deployed without prior notice.


Vulnerability Assessments

From time to time, Aira Hosting may perform security assessments, operational reviews, configuration evaluations, or other activities designed to identify and reduce security risks within systems under our control.

These activities may be conducted using internal personnel or trusted third-party service providers.


Malware Detection

Where feasible, Aira Hosting may use automated or manual processes to identify indicators of malicious activity, including:

  • Malware.
  • Web shells.
  • Phishing content.
  • Spam scripts.
  • Botnet software.
  • Cryptocurrency mining software.
  • Malicious redirects.
  • Known exploit files.

Detection of malicious content does not create an obligation for Aira Hosting to clean, repair, recover, or restore customer websites unless such services are expressly included in the customer’s hosting plan or a separate support agreement.


Actions We May Take

If Aira Hosting reasonably believes that a customer account, server, website, or application poses a security risk, we may, without prior notice where necessary:

  • Restrict access to affected services.
  • Temporarily suspend services.
  • Block malicious network traffic.
  • Disable compromised accounts.
  • Isolate affected systems.
  • Remove or quarantine malicious files where operationally appropriate.
  • Require password resets.
  • Request customer remediation before restoring service.

These actions are intended to protect our infrastructure, other customers, and the broader Internet ecosystem.


Customer Responsibility for Malware

Customers remain solely responsible for maintaining secure applications and preventing malware infections within their hosted environments.

This includes:

  • Updating software.
  • Removing vulnerable plugins.
  • Reviewing user accounts.
  • Maintaining secure passwords.
  • Scanning websites for malware.
  • Restoring from backups where necessary.

Aira Hosting is not responsible for losses resulting from malware introduced through customer software, customer credentials, insecure applications, third-party extensions, or customer negligence.

14. Security Incident Response

Aira Hosting maintains procedures for responding to suspected security incidents affecting systems under our operational control. Our objective is to identify, contain, investigate, and remediate incidents in a timely and reasonable manner while minimizing disruption to customers and protecting the stability of our platform.

Our incident response process may include:

  • Detection of suspicious activity through monitoring or third-party reports.
  • Initial assessment of the nature and potential impact of the incident.
  • Containment measures to prevent further compromise.
  • Investigation of affected systems and available evidence.
  • Remediation of confirmed security issues where appropriate.
  • Restoration of affected services when reasonably possible.
  • Internal review to identify lessons learned and improve future security practices.

Where required by applicable law or where we determine it is appropriate, we may notify affected customers of confirmed security incidents involving systems under our control. The timing, content, and method of any notification will be determined by the circumstances of the incident, legal obligations, and the need to protect ongoing investigations.

Nothing in this section guarantees a specific response time, resolution time, or customer notification timeframe.


15. Customer Security Responsibilities

Customers play a critical role in maintaining the security of their hosting environment. Aira Hosting cannot secure customer-managed websites, applications, or data without customer cooperation.

Customers are responsible for, among other things:

  • Maintaining strong and unique passwords for all accounts.
  • Enabling multi-factor authentication where available.
  • Keeping operating systems, applications, CMS platforms, plugins, themes, and scripts up to date.
  • Removing unused software, plugins, themes, and accounts.
  • Reviewing access permissions regularly.
  • Protecting SSH keys, API keys, FTP credentials, and other authentication secrets.
  • Securing personal devices used to access hosting services.
  • Monitoring websites and applications for suspicious activity.
  • Maintaining independent backups of important data.
  • Promptly reporting suspected security issues to Aira Hosting.
  • Complying with all applicable laws and the Aira Hosting Terms of Service and Acceptable Use Policy.

Failure to maintain appropriate security practices may increase the risk of unauthorized access, malware infection, data loss, or service disruption. Aira Hosting shall not be liable for security incidents resulting from customer actions, omissions, or failure to follow reasonable security practices.


16. Backup and Data Protection

Certain hosting plans may include backup features or backup-related services. Unless expressly stated in a separate agreement or service description:

  • Backups are provided as a convenience only.
  • Backup schedules, retention periods, and restoration capabilities may vary by service.
  • We do not guarantee that backups will be created, retained, complete, error-free, or recoverable.
  • Customers remain solely responsible for maintaining current and independent copies of all important data.

Customers should regularly verify the integrity of their own backups and maintain additional copies in locations under their own control.

Aira Hosting shall not be responsible for data loss, corrupted backups, failed restorations, or any damages arising from the absence or unavailability of backup data.


17. Third-Party Services and Providers

To deliver our services, Aira Hosting may rely on third-party providers, including but not limited to:

  • Data center operators.
  • Cloud infrastructure providers.
  • Domain registrars.
  • DNS service providers.
  • Payment processors.
  • Email service providers.
  • Content delivery networks (CDNs).
  • Security and monitoring vendors.

While we select providers that we believe are reputable and suitable for our operations, we do not own or control their systems. Their services are subject to their own security practices, terms, and policies.

Accordingly, Aira Hosting does not guarantee the security, availability, or performance of any third-party service and shall not be responsible for outages, data loss, breaches, delays, or other issues arising from systems outside our direct control.


18. Responsible Vulnerability Disclosure

Aira Hosting welcomes responsible disclosure of legitimate security vulnerabilities affecting our publicly accessible services.

If you believe you have discovered a security issue, please report it to:

Security Contact: security@airahosting.com

When submitting a report, please include:

  • A description of the issue.
  • Steps to reproduce the issue, if applicable.
  • The affected service or URL.
  • Supporting screenshots, logs, or proof of concept where appropriate.
  • Your contact information for follow-up.

Individuals reporting vulnerabilities are expected to:

  • Act in good faith.
  • Avoid exploiting vulnerabilities beyond what is reasonably necessary to demonstrate the issue.
  • Avoid accessing, modifying, or deleting customer data.
  • Avoid disrupting services or degrading availability.
  • Maintain confidentiality until the issue has been reviewed and addressed.

Aira Hosting reserves the right to determine whether a reported issue constitutes a security vulnerability and how it will be addressed.


19. Prohibited Security Activities

Without our prior written authorization, customers and third parties must not engage in activities intended to test, circumvent, or compromise the security of Aira Hosting systems.

Prohibited activities include, but are not limited to:

  • Unauthorized vulnerability scanning.
  • Port scanning of Aira Hosting infrastructure.
  • Denial-of-service or distributed denial-of-service attacks.
  • Brute-force login attempts.
  • Password guessing.
  • Credential stuffing.
  • Unauthorized penetration testing.
  • Packet interception or network sniffing.
  • Attempting to bypass authentication controls.
  • Reverse engineering security mechanisms.
  • Installing malware or malicious scripts.
  • Exploiting known or suspected vulnerabilities.
  • Interfering with monitoring or logging systems.

Violations may result in immediate suspension or termination of services and may be reported to relevant authorities where appropriate.


20. Security Limitations

Although Aira Hosting implements commercially reasonable safeguards, no online service, hosting platform, or technology can guarantee complete protection against every security threat.

Customers acknowledge that security risks may include, without limitation:

  • Zero-day vulnerabilities.
  • Sophisticated cyberattacks.
  • Distributed denial-of-service attacks.
  • Supply chain compromises.
  • Internet infrastructure failures.
  • Hardware failures.
  • Software defects.
  • Human error.
  • Customer negligence.
  • Credential theft.
  • Malware introduced by customers.
  • Third-party service failures.
  • Force majeure events.

Accordingly, Aira Hosting does not represent or warrant that its services will be completely secure, uninterrupted, error-free, or immune from compromise.


21. Limitation of Liability

To the fullest extent permitted by applicable law, Aira Hosting shall not be liable for any direct, indirect, incidental, consequential, special, exemplary, or punitive damages arising out of or related to:

  • Security incidents.
  • Unauthorized access.
  • Cyberattacks.
  • Malware infections.
  • Data loss.
  • Data corruption.
  • Service interruptions.
  • Business interruption.
  • Lost profits.
  • Lost revenue.
  • Loss of business opportunities.
  • Loss of goodwill.
  • SEO or search ranking impacts.
  • Customer misconfiguration.
  • Failure to maintain backups.
  • Customer negligence.
  • Third-party service failures.
  • Delays in detecting or responding to security incidents.

Nothing in this Security Policy limits any liability that cannot be excluded or limited under applicable law. Additional limitations of liability are set out in the Aira Hosting Terms of Service, which govern in the event of any inconsistency.


22. Changes to This Security Policy

Aira Hosting may update, revise, or replace this Security Policy from time to time to reflect:

  • Changes in our services.
  • Changes in technology.
  • Operational improvements.
  • Legal or regulatory requirements.
  • Industry best practices.
  • Security developments.

Updated versions become effective when published on the Aira Hosting website unless a different effective date is stated.

Customers are encouraged to review this Security Policy periodically to remain informed about our security practices.


23. Contact Us

If you have questions about this Security Policy or wish to report a security concern, please contact us using the appropriate channel.

General Support: support@airahosting.com

Security Reports: security@airahosting.com

Abuse Reports: abuse@airahosting.com

Please provide sufficient information to help us investigate your request, including relevant account details, affected services, timestamps, and supporting evidence where available.


24. Final Statement

Security is an ongoing process rather than a single feature. Aira Hosting is committed to continually improving its operational security practices as our business and services evolve.

At the same time, customers acknowledge that no hosting provider can eliminate all security risks. By using our services, customers accept the shared responsibility model described in this Security Policy and agree to take reasonable steps to protect their own applications, data, credentials, and hosted environments.

Share:

We provide reliable, secure, and high-performance hosting solutions tailored to your needs, ensuring fast, scalable, and hassle-free online experiences.

Get Connected

@ 2026 Aira Hosting All Right Reserved. Designed By Grolabs Studio