Security Policy

Effective Date June 30, 2026
Last Updated July 26, 2026
Review Cycle Every 12 Months

Security is a fundamental component of the design, operation, and continuous improvement of Apex Thunder Services. We implement administrative, technical, and organizational safeguards designed to protect our infrastructure, customer data, networks, systems, and hosted services against unauthorized access, disclosure, alteration, destruction, misuse, and other security threats. This Security Policy outlines the principles, controls, and practices that support the confidentiality, integrity, availability, and resilience of our Services. This Policy is provided for informational purposes and does not create any contractual warranties or guarantees regarding the absolute security of the Services or Customer Data.

Purpose of this Policy

The purpose of this Security Policy is to provide Customers with a high-level overview of the security practices implemented by Apex Thunder. Certain operational controls, internal procedures, technical safeguards, and defensive configurations are intentionally omitted to prevent disclosure of information that could be exploited by malicious actors. Security measures are dynamic and subject to modification at Apex Thunder's sole discretion to address evolving threats.

This Policy should be read in conjunction with our Privacy Policy, Data Processing Agreement (GDPR), Acceptable Use Policy, Terms of Service, and other documents available within the Apex Thunder Legal Center. In the event of a conflict, the Terms of Service shall prevail.

1. Security Governance

Apex Thunder maintains a security governance framework designed to protect the confidentiality, integrity, availability, and resilience of its infrastructure, systems, networks, Services, and Customer Data. Security is integrated into operational processes, technical design, risk management, and ongoing business activities to support the secure delivery of our Services and compliance with applicable legal, contractual, and regulatory obligations.

1.1 Security Principles

Apex Thunder designs and operates its Services according to recognized information security principles, including least privilege, defense in depth, segregation of duties, secure-by-default configurations, risk-based decision making, continuous monitoring, and continuous improvement. Security controls are selected and implemented based on the nature of the Services, identified risks, operational requirements, and industry best practices. These controls do not constitute a guarantee of absolute security.

1.2 Security Program

Apex Thunder maintains administrative, technical, and organizational measures designed to identify, evaluate, manage, and reduce security risks affecting its infrastructure and Services. Security practices are periodically reviewed and may be updated, modified, or retired at Apex Thunder's sole discretion to address emerging threats, technological developments, operational requirements, and evolving legal or regulatory expectations.

1.3 Risk Management

Security risks are continuously assessed throughout the lifecycle of our Services. Identified risks are prioritized according to their potential impact and likelihood, and appropriate mitigation measures are implemented to reduce risks to acceptable operational levels. Apex Thunder reserves the right to allocate security resources based on overall risk assessment and operational priorities.

1.4 Policies & Internal Procedures

Apex Thunder maintains internal security policies, operational procedures, and technical standards governing areas including access management, infrastructure security, incident response, change management, system administration, vulnerability management, data protection, and acceptable use. Internal security documentation is strictly confidential and is not publicly disclosed except where explicitly required by law or enforceable contractual obligations.

1.5 Security Awareness

Personnel with responsibilities relating to the operation, administration, or support of the Services are required to understand and comply with applicable internal security requirements, confidentiality obligations, and operational procedures appropriate to their respective roles. Personnel are subject to ongoing training and compliance monitoring.

1.6 Continuous Improvement

Information security is an ongoing process rather than a one-time implementation. Apex Thunder regularly reviews its security posture and may modify policies, procedures, technologies, and operational practices at its sole discretion to improve resilience, strengthen defenses, address newly identified risks, and support the secure delivery of current and future Services.

2. Physical Infrastructure Security

Apex Thunder relies on professionally managed data center facilities and infrastructure providers that implement physical security measures designed to protect servers, networking equipment, storage systems, and supporting infrastructure against unauthorized access, environmental hazards, theft, vandalism, and service disruptions. Physical security forms an essential component of our overall information security strategy and supports the continuous availability and resilience of our Services.

2.1 Secure Data Center Facilities

Customer Services are hosted within professionally managed data center environments designed to provide high levels of physical protection, environmental stability, operational resilience, and infrastructure redundancy appropriate for modern cloud and hosting services.

2.2 Controlled Physical Access

Physical access to data center facilities is restricted to authorized personnel with a legitimate operational need. Access is controlled through multiple authentication mechanisms and is subject to monitoring, logging, and other security procedures implemented by the facility operator.

2.3 Surveillance & Facility Monitoring

Data center environments utilize continuous surveillance systems, security personnel, access logging, intrusion detection, and other monitoring technologies designed to detect unauthorized access attempts and support the physical security of critical infrastructure.

2.4 Environmental Protection

Physical infrastructure is protected through environmental controls designed to maintain appropriate operating conditions. These controls include temperature regulation, humidity management, fire detection and suppression systems, water leak monitoring, and other measures designed to reduce the risk of environmental damage to critical systems.

2.5 Power & Infrastructure Redundancy

Data center facilities incorporate redundant electrical systems, backup power supplies, uninterruptible power systems (UPS), standby generators, redundant networking equipment, and other infrastructure designed to reduce the impact of hardware failures or utility interruptions on the availability of the Services.

2.6 Hardware Lifecycle Management

Storage devices and other hardware components are managed throughout their operational lifecycle. Equipment that is repaired, replaced, retired, or disposed of is handled using procedures designed to reduce the risk of unauthorized access to Customer Data and other confidential information, consistent with applicable operational and security requirements.

2.7 Third-Party Facility Providers

Where Apex Thunder utilizes third-party data center providers, cloud infrastructure providers, or colocation facilities, those providers are contractually obligated to maintain physical security controls appropriate for the Services they deliver. While Apex Thunder carefully selects infrastructure partners, certain aspects of physical facility security remain under the operational control of the respective facility operators. Apex Thunder shall not be liable for physical security failures attributable to third-party facility operators beyond the scope of standard industry practices.

3. Network Security

Apex Thunder implements multiple layers of network security controls designed to protect its infrastructure, Services, and Customer Data from unauthorized access, malicious activity, network abuse, and other cyber threats. Security measures are continuously evaluated and may be enhanced at Apex Thunder's discretion to address emerging risks, evolving attack techniques, and operational requirements while maintaining the availability, integrity, and confidentiality of our Services.

3.1 Defense in Depth

Our network security strategy follows a defense-in-depth approach that combines multiple technical, administrative, and operational controls across different layers of the infrastructure. This layered approach reduces the likelihood that a single control failure will compromise the overall security of the Services.

3.2 Firewalls & Traffic Filtering

Network traffic is protected using firewalls, access control mechanisms, routing policies, and traffic filtering technologies designed to restrict unauthorized connections, limit unnecessary network exposure, and reduce the attack surface of publicly accessible systems.

3.3 DDoS Protection

Apex Thunder utilizes distributed denial-of-service (DDoS) mitigation technologies, traffic analysis, rate limiting, and upstream protection services designed to reduce the impact of malicious traffic targeting the availability of the Services. DDoS mitigation is provided on a best-effort basis. No mitigation solution can guarantee complete protection against every attack. Apex Thunder reserves the right to suspend or terminate Services if a Customer's account is identified as the source of malicious traffic or DDoS attacks.

3.4 Network Segmentation

Network resources are logically segmented to separate management systems, production environments, administrative services, storage networks, and other infrastructure components. Segmentation reduces the potential impact of security incidents and limits unauthorized lateral movement within the infrastructure.

3.5 Secure Communications

Apex Thunder supports the use of secure communication protocols and encrypted network connections where appropriate to protect data transmitted between Customers, administrative systems, APIs, management interfaces, and other supported Services.

3.6 Network Monitoring

Network activity is continuously monitored to identify abnormal behavior, malicious traffic, unauthorized access attempts, service abuse, operational anomalies, and other events that could affect the security or availability of the Services. Security events are investigated as part of our incident response procedures. Monitoring is conducted solely for security and operational purposes and does not constitute a warranty of uninterrupted service.

3.7 Network Resilience

Network architecture is designed with resilience in mind and includes redundant connectivity, multiple upstream providers, failover capabilities, traffic balancing, and other operational safeguards designed to minimize service disruption resulting from hardware failures, connectivity issues, or network-related incidents.

3.8 Continuous Improvement

Apex Thunder periodically reviews its network architecture, security controls, threat intelligence, and operational procedures to improve protection against evolving cyber threats. Network security technologies, detection capabilities, and defensive measures may be updated, modified, or replaced without prior notice whenever necessary to maintain the security and reliability of the Services.

4. Access Control & Authentication

Apex Thunder implements access control and authentication measures designed to ensure that access to Customer Data, administrative systems, internal services, and supporting infrastructure is limited to authorized individuals with a legitimate business need. Access management follows recognized security principles designed to minimize risk while supporting the secure operation and maintenance of the Services.

4.1 Principle of Least Privilege

Access rights are granted according to the principle of least privilege. Personnel are provided only with the minimum level of access reasonably necessary to perform their assigned responsibilities. Privileges are reviewed periodically and may be modified or revoked at Apex Thunder's discretion whenever operational, security, or business requirements change.

4.2 Authentication Controls

Administrative systems, management interfaces, and other sensitive resources are protected through appropriate authentication mechanisms designed to prevent unauthorized access. Authentication methods may evolve over time as security technologies and operational requirements continue to develop.

4.3 Multi-Factor Authentication

Where appropriate and reasonably practicable, Apex Thunder supports or requires the use of multi-factor authentication (MFA) for administrative access and other security-sensitive systems. Customers are strongly encouraged to enable MFA wherever it is available to provide an additional layer of account protection. Failure to enable MFA when available does not relieve Apex Thunder of its obligations, but may result in reduced support eligibility for credential-related incidents.

4.4 Account Management

User accounts are managed throughout their lifecycle using procedures designed to ensure that access is granted, modified, suspended, or removed in a timely manner. Dormant, unnecessary, or obsolete accounts may be disabled or removed where appropriate to reduce security risks.

4.5 Administrative Access

Administrative access to production systems is restricted to authorized personnel whose duties require such access. Administrative activities are monitored, logged, and reviewed to support operational security, accountability, troubleshooting, and incident investigations where appropriate.

4.6 Password Security

Customers are solely responsible for maintaining the confidentiality of their account credentials and for selecting strong, unique passwords. Apex Thunder recommends using password managers, enabling multi-factor authentication where available, and avoiding the reuse of passwords across multiple services. Apex Thunder shall not be liable for unauthorized access or data loss resulting from compromised credentials, customer negligence, or failure to follow security best practices.

4.7 Session Security

Session management controls include secure session handling, automatic session expiration, inactivity timeouts, account lockout mechanisms, and other protective measures designed to reduce the risk of unauthorized account access or session hijacking where appropriate for the Services.

4.8 Continuous Review

Apex Thunder periodically reviews access management practices, authentication technologies, and account security controls to strengthen protection against evolving threats, improve operational security, and support compliance with applicable legal, regulatory, and contractual requirements.

5. Data Protection & Encryption

Apex Thunder implements administrative, technical, and organizational measures designed to protect Customer Data throughout its lifecycle. Security controls are intended to preserve the confidentiality, integrity, and availability of information while supporting secure storage, transmission, processing, and disposal of data. Encryption and other protective technologies are applied where appropriate, taking into account the nature of the Services, operational requirements, applicable legal obligations, and industry best practices.

5.1 Data Protection Principles

Customer Data is protected using layered security controls designed to reduce the risk of unauthorized access, disclosure, modification, destruction, or accidental loss. Data protection measures are regularly evaluated and may be enhanced in response to emerging threats, technological developments, and operational requirements.

5.2 Encryption in Transit

Where appropriate, data transmitted between Customers, web applications, administrative interfaces, APIs, and supporting services is protected using modern encrypted communication protocols. Secure transmission helps safeguard sensitive information from interception, tampering, and unauthorized disclosure while data is in transit across public or private networks.

5.3 Encryption at Rest

Depending on the Services provided and the underlying infrastructure, Customer Data or storage media may be protected using encryption or other appropriate storage security mechanisms. The availability, implementation, and management of encryption at rest may vary based on the specific Service, infrastructure, storage technology, and operational requirements. Customers requiring specific encryption key management should consult their Service agreement or contact Apex Thunder prior to onboarding.

5.4 Backup Protection

Where backup services are provided, backup data is protected through appropriate administrative, technical, and physical safeguards designed to preserve confidentiality, integrity, and availability. Backup retention periods, storage locations, and recovery procedures are managed in accordance with operational requirements and the applicable Service. Backups are not a substitute for Customer-maintained data redundancy.

5.5 Secure Data Disposal

When Customer Data is deleted or storage media reaches the end of its operational lifecycle, reasonable measures are implemented to securely remove, overwrite, destroy, or otherwise render the information inaccessible, taking into account the storage technology, operational environment, and applicable industry practices.

5.6 Data Integrity

Apex Thunder implements operational controls designed to help maintain the accuracy, consistency, and integrity of Customer Data throughout processing activities. Measures include access controls, change management procedures, system validation, monitoring, and other appropriate safeguards designed to reduce the risk of unauthorized or unintended data modification.

5.7 Customer Responsibilities

Customers remain solely responsible for protecting the confidentiality of their own information, maintaining appropriate local backups, securely managing encryption keys, credentials, authentication devices, and implementing any additional security controls required for their applications, users, or regulatory obligations. Apex Thunder is not liable for data loss or corruption resulting from Customer negligence, failure to maintain backups, or unauthorized access to Customer credentials.

5.8 Continuous Improvement

Apex Thunder periodically reviews its data protection practices, encryption technologies, storage security controls, and operational procedures to strengthen the protection of Customer Data and maintain alignment with evolving security standards, regulatory expectations, and technological advancements.

6. Monitoring & Threat Detection

Apex Thunder continuously monitors its infrastructure, networks, systems, and Services to help identify operational anomalies, unauthorized activities, security threats, and other events that may affect the confidentiality, integrity, or availability of Customer Data and the Services. Monitoring activities are designed to support early threat detection, timely incident response, operational resilience, and the continuous improvement of our security posture.

6.1 Continuous Security Monitoring

Security monitoring is performed using administrative, technical, and operational controls designed to identify suspicious behavior, unauthorized access attempts, abnormal system activity, service disruptions, configuration changes, and other indicators that may require investigation or corrective action.

6.2 Security Logging

System events, administrative activities, authentication attempts, network events, and other security-relevant actions are recorded through centralized logging mechanisms where appropriate. Log data supports operational troubleshooting, security investigations, compliance activities, and the continuous improvement of security controls.

6.3 Threat Detection

Apex Thunder utilizes automated detection technologies, behavioral analysis, threat intelligence, anomaly detection, and other security mechanisms to identify potential cyber threats, malicious activities, abuse, malware, unauthorized access attempts, or other indicators of compromise affecting the Services.

6.4 Security Event Investigation

Security events identified through monitoring activities are reviewed and investigated according to their severity, potential impact, and operational significance. Where appropriate, additional containment, mitigation, escalation, or remediation measures are implemented as part of the incident response process. Apex Thunder reserves the right to suspend affected accounts during active investigations to protect infrastructure and other Customers.

6.5 Alerting & Escalation

Security monitoring systems generate alerts for events requiring operational attention. Depending on the nature of the event, alerts are prioritized, escalated to authorized personnel, and investigated using established internal procedures designed to minimize risk and reduce potential service impact.

6.6 Log Retention & Confidentiality

Security logs and monitoring records are retained for operational, security, compliance, and troubleshooting purposes for periods determined by business, legal, or technical requirements. Access to monitoring information is restricted to authorized personnel with a legitimate business need and is protected using appropriate confidentiality and access control measures.

6.7 Continuous Improvement

Apex Thunder periodically reviews its monitoring capabilities, detection techniques, threat intelligence sources, alerting processes, and operational procedures to improve visibility into emerging threats, strengthen defensive capabilities, and enhance the overall security and resilience of the Services.

7. Security Incident Response

Apex Thunder maintains a structured security incident response program designed to identify, investigate, contain, mitigate, recover from, and learn from security incidents that may affect our infrastructure, Services, or Customer Data. Our response procedures are intended to minimize operational disruption, protect the confidentiality, integrity, and availability of systems, and support compliance with applicable legal and contractual obligations.

7.1 Incident Identification

Potential security incidents may be identified through automated monitoring systems, security alerts, internal reviews, Customer reports, threat intelligence, infrastructure monitoring, or other operational processes. Reported events are evaluated to determine their nature, scope, severity, and potential impact.

7.2 Investigation & Assessment

When a security incident is confirmed or reasonably suspected, Apex Thunder initiates an investigation to determine the affected systems, potential impact, root cause where reasonably identifiable, and appropriate response measures. Incident investigations are conducted using information reasonably available at the time.

7.3 Containment & Mitigation

Depending upon the nature of the incident, Apex Thunder may implement appropriate containment and mitigation measures to reduce further risk. Such measures may include isolating affected systems, restricting access, blocking malicious activity, applying security updates, restoring services, or implementing other reasonable technical or operational safeguards. Apex Thunder reserves the right to take any action reasonably necessary to protect its infrastructure and other Customers.

7.4 Customer Notification

Where Apex Thunder determines that a confirmed security incident or Personal Data Breach requires Customer notification under applicable law or contractual obligations, reasonable efforts will be made to notify affected Customers within the timeframes required by applicable law after sufficient information has been gathered to provide a meaningful and accurate notification. Notification may be delayed if immediate disclosure would impede investigation, remediation, or regulatory reporting obligations.

7.5 Regulatory & Legal Cooperation

Apex Thunder may cooperate with competent regulatory authorities, law enforcement agencies, and other legally authorized entities where required by Applicable Laws. Where legally permitted, Apex Thunder may notify affected Customers before disclosing Customer-related information to third parties. Apex Thunder shall not be liable for disclosures made in compliance with legal obligations or court orders.

7.6 Post-Incident Review

Following the resolution of significant security incidents, Apex Thunder may conduct internal reviews to evaluate the effectiveness of the response, identify opportunities for improvement, strengthen security controls, and reduce the likelihood of similar incidents occurring in the future.

7.7 Customer Responsibilities

Customers are required to promptly report suspected security incidents, compromised credentials, unauthorized account access, malware infections, phishing attempts, or other activities that may affect the security of their Services. Customers should maintain appropriate security practices, including protecting account credentials, enabling multi-factor authentication where available, and keeping their applications and software up to date. Delayed reporting may limit Apex Thunder's ability to mitigate damage and may affect support eligibility.

7.8 Continuous Improvement

Apex Thunder periodically reviews and enhances its incident response procedures, communication processes, monitoring capabilities, and recovery strategies to improve operational readiness, strengthen resilience, and address evolving cybersecurity threats and regulatory expectations.

8. Vulnerability Management

Apex Thunder maintains a vulnerability management program designed to identify, assess, prioritize, remediate, and continuously monitor security vulnerabilities that could affect our infrastructure, systems, applications, networks, or Services. Vulnerability management is an ongoing process that supports the secure operation of our platform and helps reduce the likelihood of successful exploitation by malicious actors.

8.1 Continuous Vulnerability Assessment

Apex Thunder periodically evaluates its infrastructure and operational environment using appropriate administrative, technical, and automated processes designed to identify known security vulnerabilities, configuration weaknesses, software defects, and other conditions that may increase security risk.

8.2 Risk-Based Prioritization

Identified vulnerabilities are evaluated based on factors including severity, exploitability, potential business impact, exposure, operational risk, and the likelihood of exploitation. Remediation activities are prioritized according to the overall level of risk presented to the Services and Customers.

8.3 Security Updates & Patch Management

Security patches, software updates, firmware updates, and configuration improvements are applied where appropriate to address identified vulnerabilities. The timing of remediation may vary depending on the severity of the vulnerability, operational considerations, compatibility requirements, maintenance schedules, and the availability of vendor-supported updates. Apex Thunder shall not be liable for vulnerabilities in third-party software or Customer-hosted applications.

8.4 Configuration Management

Secure configuration practices are implemented to reduce unnecessary system exposure and minimize security risks. System configurations are periodically reviewed and updated to align with operational requirements, industry recommendations, and evolving security best practices.

8.5 Third-Party Components

Apex Thunder may utilize third-party software, operating systems, open-source components, cloud infrastructure, and commercial technologies. Security advisories relating to these components are monitored where reasonably appropriate, and remediation measures may be implemented when necessary to reduce identified risks.

8.6 Responsible Disclosure

Apex Thunder appreciates responsible disclosure of legitimate security vulnerabilities. Individuals who believe they have identified a potential security issue are encouraged to report it through our official security or support channels. Reports submitted in good faith will be reviewed and handled in accordance with our internal security procedures. Unauthorized testing, scanning, or exploitation of Apex Thunder infrastructure or Customer Data is strictly prohibited and may result in legal action and immediate account termination.

8.7 Customer Responsibilities

Customers remain solely responsible for maintaining the security of their own applications, websites, scripts, databases, operating systems, credentials, and software installed within their hosting environments where they have administrative control. Customers should promptly apply security updates, remove unsupported software, and follow recognized security best practices. Apex Thunder is not liable for security breaches or data loss resulting from Customer software vulnerabilities or misconfigurations.

8.8 Continuous Improvement

Apex Thunder periodically reviews its vulnerability management processes, remediation procedures, security technologies, and operational controls to strengthen the overall security posture of the Services and improve resilience against newly discovered threats and evolving attack techniques.

9. Business Continuity & Disaster Recovery

Apex Thunder maintains business continuity and disaster recovery practices designed to improve the resilience of its infrastructure, reduce operational disruptions, and support the timely recovery of critical Services following security incidents, hardware failures, natural disasters, or other unexpected events. Recovery strategies are developed with consideration for operational priorities, technical feasibility, and the nature of the Services provided.

9.1 Business Continuity Planning

Apex Thunder maintains operational procedures designed to support the continued delivery of critical business functions during unexpected disruptions. Business continuity planning includes identifying essential services, maintaining operational readiness, and implementing appropriate response procedures to reduce the impact of disruptive events.

9.2 Disaster Recovery

Disaster recovery procedures are designed to facilitate the restoration of affected infrastructure, systems, applications, and operational services following significant incidents. Recovery activities are prioritized according to the severity of the incident, service dependencies, available resources, and operational requirements.

9.3 Infrastructure Resilience

Where appropriate, Apex Thunder utilizes resilient infrastructure architectures that include redundancy, failover capabilities, backup power, redundant networking, storage resilience, and other technical safeguards designed to improve service availability and minimize the impact of infrastructure failures.

9.4 Backup & Recovery

Backup services, where included within the applicable Service, are designed to support data recovery following certain operational failures or incidents. Backup frequency, retention periods, recovery capabilities, and storage methods may vary depending on the specific Service, infrastructure, and Customer's selected plan. Apex Thunder does not guarantee data recovery in all scenarios, particularly in cases of catastrophic failure, Customer-induced data corruption, or prolonged service disruption.

9.5 Recovery Prioritization

During a service disruption, recovery efforts may be prioritized according to operational impact, security considerations, infrastructure dependencies, legal obligations, and the criticality of affected Services. Recovery timelines may vary depending upon the nature and complexity of the incident and shall not constitute a guaranteed SLA unless expressly stated in a separate written agreement.

9.6 Customer Responsibilities

Customers remain solely responsible for maintaining independent backups of critical business data unless otherwise expressly provided under their Service plan. Customers should implement appropriate continuity procedures, maintain copies of essential information, and develop recovery strategies appropriate for their own operational and regulatory requirements. Apex Thunder is not liable for business interruption or data loss resulting from Customer failure to maintain independent backups.

9.7 Testing & Review

Apex Thunder may periodically review, evaluate, and improve its business continuity and disaster recovery procedures to strengthen operational resilience, validate recovery capabilities, and address changes in technology, infrastructure, security threats, and business operations.

9.8 Continuous Improvement

Business continuity and disaster recovery planning are continuously refined as operational requirements evolve. Apex Thunder may update recovery procedures, infrastructure designs, operational processes, and resilience strategies to improve preparedness, reduce risk, and enhance the reliability of the Services over time.

10. Customer Security Responsibilities

Security is a shared responsibility between Apex Thunder and its Customers. While Apex Thunder implements security controls designed to protect the underlying infrastructure and Services, Customers remain solely responsible for securing their own applications, websites, accounts, content, configurations, and activities performed within their hosting environments. Maintaining a secure environment requires ongoing attention from both parties.

10.1 Account Security

Customers are solely responsible for maintaining the confidentiality of their account credentials, administrative usernames, passwords, API credentials, SSH keys, and other authentication methods. Credentials must never be shared with unauthorized individuals and must be changed immediately if compromise is suspected. Apex Thunder shall not be liable for unauthorized access resulting from Customer negligence or credential compromise.

10.2 Multi-Factor Authentication

Customers are strongly encouraged to enable multi-factor authentication (MFA) wherever available. MFA provides an additional layer of account protection and significantly reduces the risk of unauthorized access resulting from compromised passwords.

10.3 Software Maintenance

Customers are responsible for keeping their operating systems, content management systems, applications, plugins, themes, libraries, scripts, and other installed software updated with supported and security-maintained versions. Unsupported or outdated software may expose Services to avoidable security risks. Apex Thunder is not liable for breaches resulting from unpatched Customer software.

10.4 Secure Configuration

Customers should configure their applications and hosting environments according to recognized security best practices. Unnecessary services, insecure default settings, publicly exposed administrative interfaces, and excessive user privileges should be avoided whenever reasonably possible.

10.5 Malware Prevention

Customers are responsible for taking reasonable measures to prevent malware infections, unauthorized code execution, phishing content, spam distribution, malicious scripts, and other abusive activities originating from resources under their administrative control. Apex Thunder reserves the right to suspend or terminate accounts hosting malicious content without prior notice.

10.6 Backup Responsibilities

Unless expressly included as part of the applicable Service, Customers should maintain independent, verified backups of critical data, databases, websites, application code, and configuration files. Regular backup testing is recommended to ensure that recovery can be performed when necessary.

10.7 Reporting Security Issues

Customers must promptly report suspected security incidents, compromised credentials, unauthorized account access, vulnerabilities, or other security concerns through Apex Thunder's official support or security communication channels. Early reporting helps reduce potential risks and supports timely investigation and response.

10.8 Compliance with Policies

Customers are required to comply with the Apex Thunder Terms of Service, Acceptable Use Policy, Privacy Policy, Data Processing Agreement (where applicable), and all other applicable legal policies. Failure to follow these requirements constitutes a material breach of the Service Agreement and may result in immediate suspension or termination of Services without refund or liability. Customers agree to indemnify and hold Apex Thunder harmless against any claims, damages, or losses arising from Customer security negligence, policy violations, or unauthorized access to Customer accounts.

11. Policy Updates

Apex Thunder may revise, update, or otherwise modify this Security Policy from time to time to reflect changes in security practices, technological developments, operational requirements, applicable laws, regulatory guidance, industry standards, or the Services we provide. The latest published version of this Policy supersedes all previous versions unless expressly stated otherwise.

11.1 Right to Modify

Apex Thunder reserves the right to update this Security Policy at its sole discretion whenever reasonably necessary to improve information security, address emerging cybersecurity threats, introduce new technologies, support additional Services, strengthen operational resilience, or comply with applicable legal, contractual, or regulatory requirements.

11.2 Effective Date

Unless otherwise specified, revisions to this Policy become effective on the Effective Date identified within the updated version. Continued use of the Services following the Effective Date constitutes acceptance of the revised Policy to the extent permitted by applicable law and the governing service agreement.

11.3 Material Changes

Where Apex Thunder determines that revisions materially affect this Security Policy or where notice is required by applicable law, reasonable efforts may be made to notify Customers through the Client Area, email communications, website announcements, or other appropriate communication channels. Editorial revisions, formatting updates, administrative corrections, or other non-material changes may be implemented without separate notice.

11.4 Evolving Security Practices

Cybersecurity threats, technologies, and industry standards continue to evolve. Apex Thunder may enhance, replace, or retire security controls, operational procedures, monitoring capabilities, authentication methods, encryption technologies, or other protective measures at its sole discretion whenever reasonably necessary to maintain or improve the security of the Services.

11.5 Customer Review

Customers are encouraged to review this Security Policy periodically to remain informed of updates relating to our security practices. The most current version of this Policy will always be available through the Apex Thunder Legal Center.

11.6 Relationship with Other Policies

This Security Policy should be read together with the Terms of Service, Privacy Policy, Data Processing Agreement (where applicable), Acceptable Use Policy, Cookie Policy, and other legal documentation published by Apex Thunder. Each document addresses different aspects of the contractual relationship and should be interpreted accordingly. In the event of a conflict, the Terms of Service shall prevail.

12. Contact Information

If you have questions regarding this Security Policy, wish to report a security concern, require clarification regarding our security practices, or believe you have identified a potential vulnerability affecting Apex Thunder Services, please contact us through our official communication channels. We review legitimate security-related inquiries in accordance with our internal security procedures and applicable legal obligations.

Security Inquiries

General questions regarding our security practices, infrastructure protection, operational safeguards, or this Security Policy may be submitted through our official support or legal communication channels.

Security Incident Reporting

If you suspect unauthorized access, compromised credentials, malicious activity, service abuse, or any other security incident involving Apex Thunder Services, please report the matter as soon as reasonably possible so that it can be assessed and investigated appropriately.

Responsible Vulnerability Disclosure

Individuals who identify a potential security vulnerability are encouraged to report it responsibly through our official communication channels. We request that security researchers act in good faith, avoid disrupting Services, protect Customer Data, and refrain from publicly disclosing vulnerabilities until they have been appropriately reviewed and addressed.

Customer Assistance

Customers requiring assistance with account security, authentication, access concerns, or other security-related matters should contact Apex Thunder through the Client Area or other authorized support channels so that appropriate verification procedures can be completed before assistance is provided.

Frequently Asked Questions

The following frequently asked questions provide additional information about Apex Thunder's approach to information security, infrastructure protection, Customer responsibilities, and the security practices that support our hosting Services.

How does Apex Thunder protect its infrastructure?

Apex Thunder implements administrative, technical, and organizational security measures designed to protect its infrastructure, networks, systems, and Services. Security controls are continuously reviewed and improved to address evolving cybersecurity risks and operational requirements. These measures are provided on a best-effort basis and do not constitute a guarantee of absolute security.

Is Customer Data encrypted?

Where appropriate, Apex Thunder utilizes encrypted communication protocols for data in transit and supports appropriate storage protection measures based on the applicable Service, infrastructure, operational requirements, and industry best practices. Encryption implementation may vary by Service tier and infrastructure configuration.

Does Apex Thunder protect against DDoS attacks?

Apex Thunder utilizes DDoS mitigation technologies, traffic filtering, network monitoring, and other defensive measures designed to reduce the impact of malicious traffic. However, no provider can guarantee complete protection against every attack or service disruption. Apex Thunder is not liable for downtime or losses resulting from DDoS attacks.

What should I do if I believe my account has been compromised?

You should immediately change your password, enable multi-factor authentication where available, review recent account activity, remove unauthorized access, update affected credentials, and contact Apex Thunder through our official support channels if you require assistance or believe your account has been compromised. Prompt reporting is required to mitigate potential damage.

Does Apex Thunder monitor its infrastructure?

Yes. Apex Thunder performs continuous monitoring of its infrastructure, systems, networks, and Services to help identify operational anomalies, suspicious activities, security threats, and other events requiring investigation or response. Monitoring is conducted for security and operational purposes only.

Who is responsible for securing my website or application?

Security is a shared responsibility. Apex Thunder secures the underlying hosting infrastructure, while Customers remain solely responsible for protecting their websites, applications, databases, operating systems, credentials, installed software, and content within their own hosting environments.

Are backups guaranteed for every Service?

Backup availability depends on the specific Service or hosting plan. Customers should always maintain independent backups of critical business data unless backup services are expressly included within their Service. Apex Thunder does not guarantee data recovery in all scenarios.

How are security incidents handled?

Apex Thunder follows structured incident response procedures that include identification, investigation, containment, mitigation, recovery, and post-incident review. Customers are notified where required by applicable law or contractual obligations, within the timeframes mandated by applicable regulations.

Can I report a security vulnerability?

Yes. We encourage responsible disclosure of legitimate security vulnerabilities. Reports should be submitted through our official communication channels and should avoid disrupting Services, accessing Customer Data, or performing unauthorized testing beyond what is legally permitted. Unauthorized testing is strictly prohibited.

Does this Security Policy guarantee absolute security?

No. While Apex Thunder implements reasonable administrative, technical, and organizational safeguards designed to reduce security risks, no Internet-connected system, software, network, or security control can guarantee absolute protection against every threat or security incident. Security measures are provided on a best-effort basis.

Will this Security Policy change over time?

Yes. Apex Thunder may update this Security Policy at its sole discretion to reflect changes in technology, cybersecurity threats, legal requirements, operational practices, or industry standards. The latest version will always be available through the Apex Thunder Legal Center.

Where can I learn more about Apex Thunder's legal policies?

Additional information is available through the Apex Thunder Legal Center, including our Terms of Service, Privacy Policy, Data Processing Agreement (GDPR), Cookie Policy, Acceptable Use Policy, Refund & Cancellation Policy, Support Policy, and other applicable legal documentation.