Security & trust
Practical controls, clearly described.
We use layered technical and operational controls to reduce misuse, protect infrastructure stability, and support accountable incident response.
Destination controls
Where destination hostname information is technically available, managed middleware evaluates the requested hostname against maintained policy rules before applicable traffic is forwarded.
Restricted policies cover government and public-administration systems, authentication endpoints, email authentication pages, financial institutions, cryptocurrency account or payment systems, and known abuse infrastructure.
Protocol and port controls
Nonessential outbound services and common email-delivery ports—including TCP ports 25, 465, 587, and 2525—are blocked where applicable. Workloads remain subject to protocol and destination-category controls defined by operational requirements.
Workload isolation
Applications run within controlled runtime boundaries with explicit configuration, health checks, restart observation, and resource limits. Safety-sensitive changes use resource gates and durable state so that a failed check pauses progression instead of bypassing the control.
Monitoring and response
Operational signals include workload availability, restart behavior, connection state, memory and CPU pressure, and policy events. Findings can result in rule updates, workload isolation, suspension, reconfiguration, or removal.
Responsible disclosure
To report suspected abuse or a security issue, provide the relevant date, time, destination, and supporting evidence through the appropriate channel on the Contact page.