Security & trust

Practical controls, clearly described.

We use layered technical and operational controls to reduce misuse, protect infrastructure stability, and support accountable incident response.

Destination controls

Where destination hostname information is technically available, managed middleware evaluates the requested hostname against maintained policy rules before applicable traffic is forwarded.

Restricted policies cover government and public-administration systems, authentication endpoints, email authentication pages, financial institutions, cryptocurrency account or payment systems, and known abuse infrastructure.

Protocol and port controls

Nonessential outbound services and common email-delivery ports—including TCP ports 25, 465, 587, and 2525—are blocked where applicable. Workloads remain subject to protocol and destination-category controls defined by operational requirements.

Workload isolation

Applications run within controlled runtime boundaries with explicit configuration, health checks, restart observation, and resource limits. Safety-sensitive changes use resource gates and durable state so that a failed check pauses progression instead of bypassing the control.

Monitoring and response

Operational signals include workload availability, restart behavior, connection state, memory and CPU pressure, and policy events. Findings can result in rule updates, workload isolation, suspension, reconfiguration, or removal.

No absolute security claim. No policy system can guarantee perfect categorization. Controls are reviewed and updated as new evidence, provider feedback, or abuse intelligence becomes available.

Responsible disclosure

To report suspected abuse or a security issue, provide the relevant date, time, destination, and supporting evidence through the appropriate channel on the Contact page.