Security and responsible disclosure
The safeguards that protect your services, your share of the responsibility, and how to report a vulnerability to us.
Security and Responsible Disclosure Policy
This policy describes how we approach security, how responsibility is shared with our customers, and the rules for researchers who report a vulnerability to us.
Last updated: October 5, 2026
1. Purpose and Scope
This policy applies to the upkyo.com website, the client area, the Upkyo mobile app, and all services provided by Upkyo, the trade name of a Limited Liability Company organized under the laws of the State of New Mexico, USA, company number 6867626.
It supplements our Terms of Service, Acceptable Use Policy, Privacy Policy, and Data Processing Agreement. It describes our practices for informational purposes and is not a guarantee of any particular outcome: no system connected to the internet can be protected against every risk.
2. Our Approach to Security
Security is built into how we design, operate, and evolve our services. We combine technical safeguards, organizational rules, and continuous monitoring, and we adapt them as threats change.
The measures described below may vary depending on the service you purchase. We may change them at any time, provided the overall level of protection remains equivalent or better.
3. Encryption in Transit
Connections to upkyo.com, the client area, and the mobile app are encrypted in transit using industry-standard protocols. An SSL certificate is included with our hosting plans so your own websites can also be served over an encrypted connection.
We recommend using only encrypted protocols to manage your services, such as SFTP or SSH rather than plain FTP, and automatically redirecting your websites to their secure version.
4. Infrastructure, High Availability, and Backups
Our servers are located in data centers within the European Union, operated by infrastructure partners selected for their physical security, redundancy, and continuity measures. Our hosting servers are paired in a high-availability setup, with an uptime target of 99.99%.
Hosting includes an automatic backup every hour. These backups are a convenience designed to make restores easier. They do not replace the copies you must keep yourself, as explained in our Backup and Retention Policy.
5. Protection Against Attacks and Malware
Our services are protected by DDoS mitigation that filters malicious traffic and limits the impact of flooding attacks. Anti-malware tools scan hosting environments to detect suspicious files and behavior.
When malicious content is detected, we may quarantine or neutralize it, restrict access to the affected service, or ask you to take action. These tools reduce risk but cannot guarantee that every threat will be detected.
6. Access Control
Access to our internal systems is limited to people who need it to do their jobs, following the principle of least privilege. Access is tied to named individuals, protected by strong authentication, and removed as soon as it is no longer needed.
Our team members and contractors are bound by confidentiality obligations. We access the content of your services only when needed to provide the service, handle a support request, maintain security, or comply with a legal obligation.
7. Updates and Patching
We apply security updates and patches to the systems we manage, including shared servers, hosting platforms, and client area tools, based on their severity and on stability requirements.
On unmanaged VPS, cloud, or dedicated servers, the operating system and any software you install are your responsibility unless the plan description says otherwise. Urgent maintenance may require a brief service interruption, which we work to keep as short as possible.
8. Monitoring and Logging
Our team and tools continuously monitor the health of our infrastructure, intrusion attempts, and unusual activity. Our 24/7 human support team can respond to alerts at any time.
We keep technical logs to maintain security, investigate incidents, and meet our legal obligations, as described in our Privacy Policy.
9. Shared Responsibility
Securing your services is a shared effort. Upkyo is responsible for the security of the infrastructure it operates or has operated on its behalf: the network, physical servers, virtualization layers, shared hosting platforms, and client area tools.
You are responsible for everything you install, configure, or publish: your credentials, applications, CMS, themes and plugins, scripts, content, the access you grant to others, and, on unmanaged servers, the operating system and its configuration. A vulnerability in any of these is your responsibility, even if it affects a service hosted with Upkyo.
10. Your Security Best Practices
Use long, unique passwords stored in a password manager. Turn on two-factor authentication for your client area, your applications, and your email whenever it is available.
Keep your CMS, themes, plugins, and libraries up to date; remove anything you no longer use, and install components only from trusted sources. Limit the permissions of the accounts you create, secure the devices you sign in from, and keep your own backups outside our servers.
Upkyo will never ask for your password by email, message, or phone. If you are unsure whether a message really comes from us, contact us through your client area.
11. Actions We May Take
To protect our customers, our systems, or third parties, we may, without notice when urgency requires it, suspend or isolate a service, block traffic or an address, disable a script, reset credentials, quarantine files, or limit resources.
We will tell you about the action taken and why as soon as possible, unless the law or security concerns prevent it. These actions are taken under our Terms of Service and do not entitle you to compensation when they result from a risk connected to your service.
12. Incident Management
Every suspected security incident is investigated. We work to contain it, identify its cause and scope, restore service, and then take the steps needed to prevent it from happening again. Significant incidents are documented.
If you notice an incident affecting your own service, a compromise of your credentials, or suspicious activity, let us know right away at support@upkyo.com or by opening a ticket in your client area.
13. Customer Notification
If a security incident affects your services or data we process on your behalf, we will notify you without undue delay by email or in your client area. We will share the information available to us: the nature of the incident, the categories of data involved, its likely consequences, and the measures taken or proposed.
Where you act as a controller under the GDPR, this notice is meant to help you meet your own obligation to notify the supervisory authority within 72 hours under Article 33 of the GDPR. We also comply with the breach notification requirements of applicable U.S. laws. Further details are set out in our Data Processing Agreement.
14. Responsible Disclosure: How to Report a Vulnerability
If you believe you have found a vulnerability in a service operated by Upkyo, email support@upkyo.com with “Security report” in the subject line.
To help us act quickly, include: the affected service, address, or component; the type of vulnerability; detailed steps to reproduce it; a harmless proof of concept; the impact you believe is possible; the date you discovered it; and how you would like to be contacted. Do not include other people’s personal data in your report. If you are unsure whether a test is allowed, ask us before you run it.
15. In Scope
The following are covered by this policy: upkyo.com and subdomains operated directly by Upkyo; the client area; the Upkyo mobile app; and the APIs and infrastructure Upkyo operates to deliver its services.
You may test only accounts and services that belong to you, or for which you have the owner’s explicit permission.
16. Out of Scope
The following are out of scope: websites, applications, and content hosted by our customers, which you should report to their owner or, in case of unlawful use, through our Abuse Reporting process; third-party services, including payment providers, the domain registrar, and NordVPN, which run their own programs; and our partners’ infrastructure.
The following are generally not considered valid findings: reports from automated tools with no demonstrated impact; missing security headers with no exploitation scenario; version number disclosure; clickjacking on pages with no sensitive actions; issues that require an outdated browser, a compromised device, or unlikely victim interaction; issues that affect only your own session; and comments on email record configuration with no demonstrated abuse.
17. Prohibited Activities
While conducting research, you must not: access, copy, modify, or delete data belonging to other customers or third parties beyond the minimum strictly necessary to demonstrate the vulnerability; cause a denial of service, overload our systems, or run load tests; use social engineering, phishing, or any manipulation of our staff, contractors, or customers; perform physical testing of offices, data centers, or equipment; send unsolicited messages; install a backdoor or any persistent access; or use a vulnerability to pivot to other systems.
If you accidentally access data that does not belong to you, stop testing immediately, keep no copies, and tell us. Any demand for payment presented as a condition for not disclosing a vulnerability will be treated as attempted extortion.
18. Safe Harbor for Good Faith Research
If you act in good faith and follow this policy, we will consider your research authorized. We will not bring legal action or file a complaint against you for that research, including under the Computer Fraud and Abuse Act, the anti-circumvention provisions of the Digital Millennium Copyright Act, or similar laws in other countries. If a third party takes legal action against you for activities that comply with this policy, we will make it known that those activities were authorized.
This commitment binds Upkyo only: it cannot bind our customers, our partners, other third parties, or public authorities. It does not apply to conduct that violates this policy or the law.
19. Our Commitments to You
When you send us a report that follows this policy, we will acknowledge it within a reasonable time, review it seriously, keep you informed of our progress, and let you know when the vulnerability has been fixed.
With your permission, we may thank you publicly by name or handle. We will not share your contact details with third parties without your consent, unless required by law.
20. No Guaranteed Reward
Upkyo does not run a bug bounty program. At our sole discretion, we may offer thanks or a reward for a particularly helpful report, but no report creates a right to payment, regardless of its severity.
No reward can be paid where prohibited by law, including to persons subject to economic sanctions. Any reward is subject to the recipient’s own tax obligations.
21. Confidentiality Until a Fix Is Available
You agree to keep all information about the vulnerability confidential until it has been fixed and we have agreed together on any public disclosure. We may ask you to delay disclosure if our customers need time to apply a fix.
Once the issue is resolved, you must delete any data you may have obtained during testing. We may publish our own security advisory.
22. Changes to This Policy
We may change this policy at any time. The version that applies is the one published on upkyo.com at the time of your research or report. Material changes that affect our customers are announced by email or in the client area.
This policy is published in several languages. If the versions differ, the English version controls.
23. Contact
For security reports or questions about this policy: support@upkyo.com, or open a ticket in your client area.
Mailing address: Upkyo, 1178 Broadway, 3rd Floor #1249, New York, NY 10001, USA.