Effective Date: July 7, 2026
Last Updated: July 7, 2026
At Aira Hosting (“Aira Hosting”, “we”, “our”, or “us”), protecting the confidentiality, integrity, and availability of our hosting platform is one of our highest operational priorities. We implement commercially reasonable administrative, technical, and physical safeguards designed to help protect our infrastructure and the services we provide to customers.
This Security Policy explains our general approach to safeguarding our hosting environment, customer accounts, and supporting systems. It also outlines the respective security responsibilities of both Aira Hosting and our customers.
Security is a shared responsibility. While we maintain and secure the infrastructure under our control, customers are responsible for maintaining the security of the applications, websites, data, credentials, and software they deploy on our platform.
This Security Policy should be read together with our:
If any conflict exists between this Security Policy and our Terms of Service, the Terms of Service shall prevail.
Nothing in this Security Policy creates a contractual guarantee, warranty, certification, or representation that any service is completely secure, uninterrupted, or immune from cyber threats.
The purpose of this Security Policy is to:
This document is intended for informational purposes only and does not constitute a guarantee of any particular level of security or compliance.
This Security Policy applies to the security of systems, services, and infrastructure operated or managed directly by Aira Hosting, including, where applicable:
The security measures described in this policy apply only to systems under the operational control of Aira Hosting.
Unless expressly agreed in writing, this Security Policy does not apply to:
Customers remain solely responsible for securing these assets.
Our security program is based on practical industry practices appropriate for the size and nature of our business and focuses on the following core principles:
We implement reasonable safeguards intended to reduce unauthorized access to systems and information under our control.
We work to protect hosted infrastructure from unauthorized modification through access controls, authentication mechanisms, logging, and operational procedures.
We strive to maintain reliable service availability through infrastructure monitoring, redundancy where appropriate, routine maintenance, and operational planning. However, uninterrupted availability cannot be guaranteed.
Cybersecurity is an evolving field. We regularly review our operational practices and may improve, replace, or modify security controls as technology, threats, legal requirements, or business operations change.
Security within a hosting environment is a shared responsibility between Aira Hosting and each customer.
Understanding these responsibilities is essential for maintaining a secure hosting environment.
Aira Hosting is generally responsible for protecting the infrastructure that we own or directly manage, including:
These responsibilities apply only to infrastructure operated or managed by Aira Hosting.
Customers remain fully responsible for securing everything they install, upload, configure, or manage within their hosting accounts.
This includes, but is not limited to:
Failure to properly secure customer-managed resources may result in unauthorized access, malware infections, data loss, or service interruption, for which Aira Hosting shall not be responsible.
Customers agree to cooperate with Aira Hosting during security investigations by:
Failure to cooperate may result in temporary suspension or restriction of services where necessary to protect our infrastructure, other customers, or the public.
Aira Hosting maintains internal operational procedures intended to promote the secure management of our hosting platform.
Depending on the nature and size of our operations, these procedures may include:
As a growing hosting provider, we continuously review and improve our security practices as our services evolve.
The specific technologies, vendors, software, monitoring systems, and security controls used by Aira Hosting are confidential and may be modified, replaced, enhanced, or removed at any time without prior notice for security, operational, or business reasons.
To protect our infrastructure, we do not publicly disclose detailed technical information regarding our internal security architecture, defensive technologies, monitoring capabilities, or operational procedures.
Aira Hosting implements commercially reasonable security measures intended to help protect the infrastructure used to provide our hosting services. While no security program can eliminate every risk, we continually evaluate and improve our operational practices as our business grows.
Our infrastructure security measures may include, where applicable:
Because our infrastructure may evolve over time, the specific technologies, vendors, hardware models, software, and security products used are subject to change without notice.
Nothing in this policy should be interpreted as a guarantee that infrastructure failures, hardware defects, or cyberattacks will never occur.
Protecting our network is an important component of our security program.
Depending on the services provided, Aira Hosting may implement measures such as:
Certain hosting plans may also benefit from network protections provided by upstream infrastructure providers or data center partners.
Although these controls reduce risk, they cannot completely prevent:
Service degradation or temporary interruptions may occur despite reasonable protective measures.
Aira Hosting follows reasonable operational practices to help secure servers under our management.
These practices may include:
Servers may be restarted or temporarily taken offline to apply critical security updates, perform maintenance, investigate suspected compromises, or protect the stability of the platform.
Customers acknowledge that emergency maintenance may occur without prior notice when reasonably necessary to maintain platform security.
Access to Aira Hosting systems is restricted based on operational necessity.
Administrative access is generally granted only to authorized personnel who require such access to perform legitimate business functions.
Security measures may include:
Customers are responsible for protecting access to their own hosting accounts.
Customers should:
Customers are solely responsible for all activity occurring under their account credentials unless otherwise required by applicable law.
Aira Hosting seeks to use appropriate encryption technologies to help protect data transmitted through supported services.
Depending on the service involved, protections may include:
Certain internal systems may also utilize encryption technologies for specific operational purposes.
However, customers acknowledge that:
Customers are responsible for implementing encryption within their own applications whenever appropriate.
Aira Hosting performs operational monitoring intended to identify abnormal events affecting our infrastructure.
Monitoring activities may include:
System logs may be collected for operational, troubleshooting, abuse prevention, security, legal, and compliance purposes.
To protect platform integrity, Aira Hosting reserves the right to review relevant logs when investigating:
Logging practices are carried out in accordance with our Privacy Policy and applicable laws.
Cybersecurity threats continuously evolve.
Aira Hosting monitors security developments affecting technologies used within our hosting environment and, where appropriate, applies security updates intended to reduce known risks.
The timing of updates depends on several factors, including:
Emergency updates may be deployed without prior notice.
From time to time, Aira Hosting may perform security assessments, operational reviews, configuration evaluations, or other activities designed to identify and reduce security risks within systems under our control.
These activities may be conducted using internal personnel or trusted third-party service providers.
Where feasible, Aira Hosting may use automated or manual processes to identify indicators of malicious activity, including:
Detection of malicious content does not create an obligation for Aira Hosting to clean, repair, recover, or restore customer websites unless such services are expressly included in the customer’s hosting plan or a separate support agreement.
If Aira Hosting reasonably believes that a customer account, server, website, or application poses a security risk, we may, without prior notice where necessary:
These actions are intended to protect our infrastructure, other customers, and the broader Internet ecosystem.
Customers remain solely responsible for maintaining secure applications and preventing malware infections within their hosted environments.
This includes:
Aira Hosting is not responsible for losses resulting from malware introduced through customer software, customer credentials, insecure applications, third-party extensions, or customer negligence.
Aira Hosting maintains procedures for responding to suspected security incidents affecting systems under our operational control. Our objective is to identify, contain, investigate, and remediate incidents in a timely and reasonable manner while minimizing disruption to customers and protecting the stability of our platform.
Our incident response process may include:
Where required by applicable law or where we determine it is appropriate, we may notify affected customers of confirmed security incidents involving systems under our control. The timing, content, and method of any notification will be determined by the circumstances of the incident, legal obligations, and the need to protect ongoing investigations.
Nothing in this section guarantees a specific response time, resolution time, or customer notification timeframe.
Customers play a critical role in maintaining the security of their hosting environment. Aira Hosting cannot secure customer-managed websites, applications, or data without customer cooperation.
Customers are responsible for, among other things:
Failure to maintain appropriate security practices may increase the risk of unauthorized access, malware infection, data loss, or service disruption. Aira Hosting shall not be liable for security incidents resulting from customer actions, omissions, or failure to follow reasonable security practices.
Certain hosting plans may include backup features or backup-related services. Unless expressly stated in a separate agreement or service description:
Customers should regularly verify the integrity of their own backups and maintain additional copies in locations under their own control.
Aira Hosting shall not be responsible for data loss, corrupted backups, failed restorations, or any damages arising from the absence or unavailability of backup data.
To deliver our services, Aira Hosting may rely on third-party providers, including but not limited to:
While we select providers that we believe are reputable and suitable for our operations, we do not own or control their systems. Their services are subject to their own security practices, terms, and policies.
Accordingly, Aira Hosting does not guarantee the security, availability, or performance of any third-party service and shall not be responsible for outages, data loss, breaches, delays, or other issues arising from systems outside our direct control.
Aira Hosting welcomes responsible disclosure of legitimate security vulnerabilities affecting our publicly accessible services.
If you believe you have discovered a security issue, please report it to:
Security Contact: security@airahosting.com
When submitting a report, please include:
Individuals reporting vulnerabilities are expected to:
Aira Hosting reserves the right to determine whether a reported issue constitutes a security vulnerability and how it will be addressed.
Without our prior written authorization, customers and third parties must not engage in activities intended to test, circumvent, or compromise the security of Aira Hosting systems.
Prohibited activities include, but are not limited to:
Violations may result in immediate suspension or termination of services and may be reported to relevant authorities where appropriate.
Although Aira Hosting implements commercially reasonable safeguards, no online service, hosting platform, or technology can guarantee complete protection against every security threat.
Customers acknowledge that security risks may include, without limitation:
Accordingly, Aira Hosting does not represent or warrant that its services will be completely secure, uninterrupted, error-free, or immune from compromise.
To the fullest extent permitted by applicable law, Aira Hosting shall not be liable for any direct, indirect, incidental, consequential, special, exemplary, or punitive damages arising out of or related to:
Nothing in this Security Policy limits any liability that cannot be excluded or limited under applicable law. Additional limitations of liability are set out in the Aira Hosting Terms of Service, which govern in the event of any inconsistency.
Aira Hosting may update, revise, or replace this Security Policy from time to time to reflect:
Updated versions become effective when published on the Aira Hosting website unless a different effective date is stated.
Customers are encouraged to review this Security Policy periodically to remain informed about our security practices.
If you have questions about this Security Policy or wish to report a security concern, please contact us using the appropriate channel.
General Support: support@airahosting.com
Security Reports: security@airahosting.com
Abuse Reports: abuse@airahosting.com
Please provide sufficient information to help us investigate your request, including relevant account details, affected services, timestamps, and supporting evidence where available.
Security is an ongoing process rather than a single feature. Aira Hosting is committed to continually improving its operational security practices as our business and services evolve.
At the same time, customers acknowledge that no hosting provider can eliminate all security risks. By using our services, customers accept the shared responsibility model described in this Security Policy and agree to take reasonable steps to protect their own applications, data, credentials, and hosted environments.