Security Policy

Last updated: September 13, 2026
Security practices for FinOps AI™ and every service operated by HostingX Solutions LLC. For vulnerability reports, email security@hostingx.co.il.
HostingX Solutions LLC · LLC No. 0008072296 · Founded 2026 · Registered in New Mexico, USA · 8206 Louisiana Blvd NE, Suite A #8186, Albuquerque, NM 87113, United States
Updated August 8, 2026 — some statements were narrowed. This revision corrects controls that the previous version described more broadly than we operate them. Multi-factor authentication is available and being rolled out progressively rather than required on every account; incident notification targets 72 hours where feasible rather than one hour; and several Kubernetes-platform controls that we do not operate were removed. We would rather describe fewer controls accurately than more of them aspirationally — if you evaluated us against the previous version, this is the difference.
Updated August 28, 2026 — the second factor is no longer SMS. Multi-factor authentication is now an authenticator app (TOTP): codes are computed on your own device and verified by us. No telephone number is collected for it, and no third party is involved unless a workspace selects an external provider, in which case that provider is named in Privacy §6. The previous version described SMS, which we no longer operate.

1.Our Security Commitment

HostingX Solutions LLC is committed to protecting the confidentiality, integrity, and availability of our clients' data and systems. Security is embedded in every aspect of our service delivery.

2.Data Protection

Encryption

  • All data in transit protected with TLS 1.3
  • Data at rest encrypted with AES-256
  • Encrypted backups with secure key management
  • End-to-end encryption for sensitive communications

Access Controls

  • Least-privilege access model
  • Multi-factor authentication available — an authenticator app (TOTP); enrolment is being rolled out progressively
  • Role-based access control (RBAC)
  • Regular access reviews and revocation
  • Segregation of duties for critical operations

3.Infrastructure Security

Cloud Security

  • Infrastructure hosted in SOC 2 certified data centers
  • Network segmentation and isolation
  • Web Application Firewall (WAF)
  • DDoS protection and mitigation
  • Regular security hardening

Container & Kubernetes Security

  • Dependency vulnerability scanning (Grype, against a generated SBOM) in CI
  • Non-root containers; the GCP Marketplace chart also sets a read-only root filesystem
  • Per-tenant compute isolation with IAM permissions boundaries
  • Private subnets; the origin is not internet-facing
  • Secrets held as encrypted values in AWS Systems Manager Parameter Store

4.Application Security

Development Practices

  • Secure Software Development Lifecycle (SSDLC)
  • Code review requirements
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Dependency scanning and vulnerability management

CI/CD Security

  • Pipeline security scanning
  • Immutable image tags, deployment verified by digest
  • Immutable infrastructure
  • Automated compliance checks
  • GitOps with audit trails

5.Vulnerability Management

  • Continuous vulnerability scanning
  • Risk-based prioritization
  • 24-hour patching for critical vulnerabilities
  • 7-day patching for high-severity issues
  • Monthly security updates
  • Coordinated disclosure program

6.Monitoring & Incident Response

24/7 Security Operations

  • Real-time security monitoring (SIEM)
  • Intrusion detection / prevention systems (IDS/IPS)
  • Log aggregation and analysis
  • Anomaly detection and alerting
  • Automated threat response

Incident Response

  • Documented incident response plan
  • Notification without undue delay, targeting 72 hours where feasible (Terms §9.2)
  • Forensic investigation capabilities
  • Post-incident reviews and improvements
  • Communication protocols with affected parties

7.Compliance & Auditing

Standards & Frameworks

  • Aligned with SOC 2 Type II requirements
  • CIS Benchmarks for infrastructure hardening
  • OWASP Top 10 mitigation
  • NIST Cybersecurity Framework
  • ISO 27001 control implementation (planned)

Audit & Logging

  • Comprehensive audit logging
  • A checksum stored with each audit entry when it is written, so a later edit to the entry no longer matches it
  • Application container logs kept for 30 days
  • Security audits of the application code, including an API security audit in July 2026

8.Employee Security

  • Background checks for all employees
  • Security awareness training
  • Signed confidentiality agreements
  • Clean desk and screen policies
  • Secure remote work practices

9.Vendor Security

  • Security assessment for all vendors
  • Data Processing Agreements (DPAs)
  • Regular vendor reviews
  • Subprocessor documentation
  • Supply chain risk management

10.Business Continuity

  • Disaster recovery plan with 4-hour RTO
  • Automated backups (hourly snapshots, daily full)
  • Multi-region redundancy
  • Failover procedures tested quarterly
  • Data retention policies

11.Client Responsibilities

Clients should:

  • Use strong, unique passwords
  • Enable MFA on all accounts
  • Protect API keys and credentials
  • Report security concerns promptly
  • Follow security best practices
  • Conduct their own security assessments

12.Security Reporting

Report security issues:

  • Email: security@hostingx.co.il
  • PGP key available upon request
  • Coordinated disclosure: 90-day window
  • Recognition for responsible disclosure
We do not support bug bounties but appreciate responsible disclosure.

13.Contact

Security questions
security@hostingx.co.il
General inquiries
legal@hostingx.co.il
FinOps AI inbox
hello@getfinops.cloud

FinOps AI™ is a product of HostingX Solutions LLC. These policies apply to getfinops.cloud, hostingx.co.il, and all services operated by HostingX Solutions LLC.

© 2026 HostingX Solutions LLC. LLC No. 0008072296 · 8206 Louisiana Blvd NE, Suite A #8186, Albuquerque, NM 87113, USA. All rights reserved.