Security

Security & responsible disclosure.

XenonCloud treats security as a shared responsibility. We harden our platform, monitor for abuse, and rely on customers and researchers to help keep the ecosystem safe.

How we protect your infrastructure

Security is built into our platform at multiple layers.

  • Hardened host systems with restricted access and regular patching.
  • Network-level protections including rate limiting and basic DDoS mitigation.
  • Separation of customer workloads using virtualization and strict isolation.
  • Centralized logging and monitoring for unusual activity.
  • Abuse detection via honeypots and reporting to AbuseIPDB.

Customer responsibilities

You control your instances, services, and application code. The basics go a long way.

  • Use strong SSH keys and disable password-only authentication where possible.
  • Keep operating systems, libraries, and applications patched and up to date.
  • Restrict access using firewalls, VPNs, and principle of least privilege.
  • Encrypt sensitive data at rest and in transit.

We provide the infrastructure; you remain in control of what runs on it.

Responsible disclosure

If you believe you’ve found a security issue in XenonCloud’s infrastructure, control panel, or public-facing services, we want to hear about it. We ask that you:

  • Report the issue privately and promptly.
  • Give us reasonable time to investigate and remediate before public disclosure.
  • Avoid accessing, modifying, or destroying data that does not belong to you.

Please include detailed steps to reproduce, any proof-of-concept code, and affected systems or endpoints.

How to contact our security team

To report a potential vulnerability or security concern, contact us via the contact page with “Security” in the subject line.

For highly sensitive reports, we can arrange an encrypted communication channel after initial contact.

Please do not perform denial-of-service testing or any activity that disrupts customer workloads without explicit written permission.