Snapshot 21025
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Servercore Solutions Security We safeguard the security of your projects and applications with multi-layered data protection. Our products are developed in compliance with international security standards. Contact us We Ensure Protection of IT Systems and Data at 5 Levels 01 Monitoring the data centers territory 24/7 All Servercore data centers are protected from unauthorized access by CCTV cameras that record every entry into and exit from the building. 02 Security guards at the entrance to the server rooms The buildings are equipped with turnstiles and security guards on duty. Visitors are required to present their passports and obtain visitor passes, which give them access only to permitted areas. 03 Constant monitoring of equipment racks Servercore engineers monitor the data center systems around the clock and check the performance of the servers every 3 hours. A special notification system based on tablets promptly informs them about emergency situations. 01 Strict restriction of data access Only authorized employees can access customer data after receiving approval through the internal system. Analytical data is provided in anonymized form and does not contain personal data. 02 Information security culture All employees undergo mandatory training and testing to ensure understanding of security policies. The internal security team conducts regular phishing tests to check employee vigilance. 03 Training and implementation of new practices We continuously train our employees and implement best practices in the field of information security. Our employees regularly attend conferences and are certified in information security. 01 Automation of settings We use automation to manage network settings in order to reduce human error and ensure configuration consistency. When a Servercore network engineer makes changes, they are automatically applied to all devices on the network. 02 Restricting access to the management network We isolate the management network from the internal corporate network. Only network engineers and technicians who maintain equipment can access network equipment management and monitoring functions. This reduces the risks of unintentional errors and unauthorized access. 03 Isolation of projects over the network and free DDoS protection We offer three types of networks: Internet, local network, and private network of a global router. These networks are completely isolated from each other, which ensures that their operation will not be affected. Also, all customer projects are protected from DDoS attacks at the L3 and L4 levels absolutely free of charge. 01 Modular service approach in development It allows us to localize and carefully design the logic of security-sensitive products. At the same time, we minimize the impact of changes on overall operation: they may affect only limited functionality. We exclude scenarios in which an update in the production system leads to failures. 02 Isolation of customer and service infrastructure We physically and logically isolate the services we use to develop and deploy products from the services we provide to our customers. 03 Secure data deletion We take great care in deleting our customers’ data when they stop using our products. This process is automated in cloud environments. 04 Triple data replication for cloud servers We store your data in a failover cluster of network drives. Each block is stored in three copies on different servers in different racks. If one copy becomes unavailable, the system will automatically switch to using the other two. 01 Regular pentests and protection against information leaks Pentests simulate malicious attacks, allowing us to identify and fix potential vulnerabilities. Security experts are engaged for both internal and external audits. This is how we ensure that our control panel and other systems meet high security standards. 02 Use of encryption protocols and two-factor authentication When users interact with our web services, all data is encrypted, ensuring its confidentiality during transmission and preventing leaks or unauthorized access. Distribution of Responsibilities Between the Customer and Servercore Network infrastructure Hardware platform Physical security Virtualization platform Middleware, API Operating system Network security (Overlay) Application Data Customer Dedicated servers 01 Cloud servers 02 Managed Kubernetes 03 Cloud databases, object storage 04 Control panel 05 Servercore Go to control panel How to Additionally Protect Your Project We have prepared a small guide for you to apply additional measures to protect your Servercore-based infrastructure. 01 Access control How to limit access to Servercore resources. 02 Network security measures How to work with traffic filtering, IPS, etc. 03 Security event management How to log events in cloud, panel, and Managed Kubernetes. 04 Vulnerability management Tools for scanning Servercore products and services for vulnerabilities. 05 Backup How to set up backups for cloud servers, databases, and storages. 06 Antivirus protection What free antiviruses you can use. 07 Data encryption How to encrypt data on Linux servers and PostgreSQL cloud databases. 08 Managing secrets How to manage secrets in Servercore. Read the whole guide Choose the Region Where You Want to Deploy Your Service Nairobi Almaty Tashkent 1 availability zone TIER III Design TIER III ISO27001 PCI DSS Nairobi Kenya Dedicated Servers Cloud Servers Cloud Databases Managed Kubernetes 1 availability zone TIER III Design TIER III Facility ISO14001 ISO20000 ISO9001 ISO27001 ISO45000 Almaty Kazakhstan Dedicated Servers Cloud Servers Cloud Databases Managed Kubernetes 1 availability zone 2 availability zone 3 availability zone Reliability level — N+1 TIER II Tashkent Uzbekistan Dedicated Servers Cloud Servers Cloud Databases Managed Kubernetes TIER III Tashkent Uzbekistan Dedicated Servers Cloud Servers S3 Managed Kubernetes Tashkent Uzbekistan Dedicated Servers Cloud Servers Cloud Databases Managed Kubernetes Tier III data center in Nairobi Tier III infrastructure, ISO 27001 and PCI DSS certified. Keep personal data in-country and stay audit-ready under the Data Protection Act 2019. Fault tolerance level of at least 99.982% (no more than 95 minutes of downtime per year). Compliance with global and local security standards The data centers hosting Servercore products comply with DPA 2019 and GDPR standards and are PCI DSS 4.0.1 certified. Five levels of client data protection We ensure security of projects at all levels, from data centers to apps, through a range of measures, including 24/7 video surveillance, 2FA, encryption, and more. Go to control panel Servercore Licenses and Certifications Kenya Uzbekistan Kazakhstan ISO 27001 certification iCOLO It indicates that: — the information security management system of the iColo data center that hosts Servercore solutions complies with international standards, — the security of the services provided is confirmed by independent auditors, — the entry of your business into foreign markets will be significantly simplifed. Download PCI DSS certification Servercore It indicates that Servercore provides a high level of security, confirmed by an independent auditor. This allows companies to host their systems that process cardholder data. PCI DSS requirements apply to companies that process payment card data, including banks, acquiring systems, and insurance companies. Download Tier III Design certification from Uptime Institute iCOLO It ensures that in the iColo data center: — infrastructure design documentation complies with Tier III Uptime Institute standards, — multiple redundancy of communication channels and power supply is provided, — the fault tolerance ratio is at least 99.982% (no more than 95 minutes of downtime per year), — hosted services will operate even during scheduled repairs or power outages. CSA STAR Registry Servercore It confirms that Servercore’s security measures are documented in the registry under the international Cloud Controls Matrix framework — 197 controls across 17 domains, aligned with ISO 27001, PCI DSS, SOC 2, and GDPR. Follow the link ODPC Certificate of Registration Servercore It proves that Servercore has duly registered as a Data Processor with the Kenyan supervisory authority, having provided sufficient information about its security measures and privacy protection practices. This certificate can be sent as requested. PCI DSS certification Servercore It indicates that Servercore provides a high level of security, confirmed by an independent auditor. This allows companies to host their systems that process cardholder data. PCI DSS requirements apply to companies that process payment card data, including banks, acquiring systems, and insurance companies. Download ISO 27001/27017/27018 Servercore ISO/IEC 27001 confirms that Servercore’s Information Security Management System (ISMS) complies with international standards and ensures strong protection of customer data. ISO/IEC 27017 extends the requirements of ISO/IEC 27001 specifically for cloud service providers. ISO/IEC 27018 complements the requirements of ISO/IEC 27001 and confirms the secure processing and protection of personal data in cloud environments. Download Download Data network license Servercore It confirms Servercore’s right to design, build, operate, and provide telecommunications networks. Download O’z Dst 2875:2014 certification UNICON It guarantees that the UNICON data center hosting Servercore solutions complies with the state standard of the Republic of Uzbekistan in the field of infrastructure and information security. Download CSA STAR Registry Servercore It confirms that Servercore’s security measures are documented in the registry under the international Cloud Controls Matrix framework — 197 controls across 17 domains, aligned with ISO 27001, PCI DSS, SOC 2, and GDPR. Follow the link PCI DSS certification Servercore It indicates that Servercore provides a high level of security, confirmed by an independent auditor. This allows companies to host their systems that process cardholder data. PCI DSS requirements apply to companies that process payment card data, including banks, acquiring systems, and insurance companies. Download ISO 27001/27017/27018 Servercore ISO/IEC 27001 confirms that Servercore’s Information Security Management System (ISMS) complies with international standards and ensures strong protection of customer data. ISO/IEC 27017 extends the requirements of ISO/IEC 27001 specifically for cloud service providers. ISO/IEC 27018 complements the requirements of ISO/IEC 27001 and confirms the secure processing and protection of personal data in cloud environments. Download Download Tier III Design certification from Uptime Institute SAIRAM It guarantees that in the Sairam data center: — infrastructure design documentation complies with Tier III Uptime Institute standards, — multiple redundancy of communication channels and power supply is provided, — the fault tolerance ratio is at least 99.982% (no more than 95 minutes of downtime per year), — hosted services will operate even during scheduled repairs or power outages. Download Tier III Facility certification from Uptime Institute SAIRAM It confirms that the Sairam data center undergoes regular independent audits for compliance with previously certified project documentation and meets the requirements of Tier III Uptime Institute. Download CSA STAR Registry Servercore It confirms that Servercore’s security measures are documented in the registry under the international Cloud Controls Matrix framework — 197 controls across 17 domains, aligned with ISO 27001, PCI DSS, SOC 2, and GDPR. Follow the link Servercore Products to Solve Your Business Tasks SLA 99.98% Cloud Servers Flexibility and scalability for any task SLA up to 100% Dedicated Servers Complete resource and performance control SLA 99.95% Managed Cloud Databases For all data types available in Servercore SLA 99.98% Managed Kubernetes Automation and container management for efficient development Request consultation