System Policies
These policies govern the acceptable use, security, resource management, backups, maintenance, and uptime commitments for all HostupCloud services. By using our services you agree to comply with these policies.
Last updated: 22 February 2026 · Effective: 22 February 2026
Acceptable Use Policy (AUP)
All customers must use HostupCloud services lawfully and responsibly. The following activities are strictly prohibited and will result in immediate account suspension without refund.
Prohibited Activities
Permitted Activities
Fair Usage & Resource Policy
Shared hosting plans operate on shared infrastructure. Excessive resource usage that degrades performance for other customers is not permitted.
CPU Usage
Sustained CPU usage above your plan's vCore allocation triggers throttling. Burst usage is permitted for short periods.
RAM
Memory is allocated per plan. Processes exceeding RAM limits are killed automatically to protect server stability.
Bandwidth
Plans operate on a fair-use basis. We do not hard-cap bandwidth, but excessive or abusive traffic patterns will be reviewed.
Inodes
Each plan has an inode limit (files + directories). Exceeding the inode limit prevents new file creation. Clean up unused files regularly.
Email Sending Limits
Security Policy
We implement multiple layers of security across all infrastructure. The following measures are active on all shared hosting accounts by default.
Imunify360
Real-time malware scanning and automatic quarantine on all shared hosting accounts.
Web Application Firewall
WAF rules active at the server level, blocking common attack vectors (SQLi, XSS, RFI).
DDoS Protection
Layer 3/4 DDoS mitigation active on all network edges. Layer 7 protection available on cloud plans.
Free SSL / TLS
Let's Encrypt SSL certificates auto-issued and auto-renewed for all domains on your account.
Account Isolation
Each hosting account runs in an isolated container. A compromised account cannot access others.
LiteSpeed + ModSecurity
LiteSpeed web server with ModSecurity rules for additional application-layer protection.
Two-Factor Authentication
2FA available on HUCPanel and billing portal. Strongly recommended for all accounts.
SSH Key Authentication
Password-based SSH login is disabled by default on cloud VPS. Key-based auth only.
Network Policy
Permitted
Prohibited
Backup Policy
We perform automated daily backups on all shared hosting plans. Backups are stored separately from the primary server.
Daily
Backup frequency
Snapshots taken every 24 hours automatically
30 Days
Retention period
Last 30 days of backups retained at no extra cost
1-Click
Restore
Restore files, databases, or full accounts from HUCPanel
Uptime SLA
HostupCloud provides a 99.9% monthly uptime guarantee on all shared hosting, cloud VPS, and dedicated server services.
99.9%
Monthly uptime SLA
≤ 43 min
Allowed downtime / month
Pro-rata
Credit for SLA breach
Maintenance Policy
Scheduled Maintenance
Window: Sunday 02:00–06:00 IST (preferred)
Notice: 48 hours advance notice via email and status page
Impact: Brief service interruption possible
Emergency Maintenance
Window: As required — no fixed window
Notice: Best-effort notice; status page updated immediately
Impact: Critical security patches or infrastructure failures
Live status and incident updates are published at status.hostupcloud.com. Subscribe to status updates to receive email notifications.
Incident Response
Our team follows a structured incident response process for all service-affecting events.
Critical
Full outage, data breach, or security compromise
High
Partial outage, degraded performance affecting multiple customers
Medium
Single customer issue or non-critical service degradation
Suspension & Termination
AUP Violation
ImmediateImmediate suspension without notice. Account reviewed; termination if violation is confirmed.
Non-payment
After noticeAccount suspended 3 days after invoice due date. Terminated and data deleted after 14 days of suspension.
Chargeback / Fraud
ImmediateImmediate account suspension. Services may be permanently terminated. Disputed amounts pursued through legal channels.
Customer Request
On requestAccount closed within 5 business days. Data deleted after 30-day grace period. No refund on remaining term.
KYC (Know Your Customer) Policy
HostupCloud conducts Know Your Customer (KYC) verification in compliance with India's Prevention of Money Laundering Act 2002 (PMLA), CERT-In Directions 70B (April 2022), and applicable AML/CFT regulations in the UK and USA. KYC is mandatory for high-value accounts, enterprise contracts, bare metal servers, colocation, and any service subject to regulatory scrutiny.
KYC Verification Providers
Stripe Identity
International customers — automated ID document + selfie verification via Stripe Identity (Stripe Inc., USA). Supports passports, national IDs, driver's licences from 30+ countries.
Cashfree KYC
India customers — PAN verification, Aadhaar offline XML KYC, and bank account verification via Cashfree Payments India Pvt. Ltd. (RBI-licensed).
Manual Verification
For customers not covered by automated flows — document upload via customer portal reviewed by our compliance team within 1–2 business days.
MOU / Enterprise KYC
Enterprise, government, and institutional customers may submit KYC under a Memorandum of Understanding (MOU) or formal contract signed by an authorised representative.
Accepted Identity Documents
🇮🇳 India
🌍 International
KYC Requirements
CERT-In Compliance — IT Act 2000 Section 70B
HostupCloud Technolabs Private Limited (India entity) is classified as an intermediary and cloud service provider under the Information Technology Act, 2000 and is subject to the CERT-In Directions under Section 70B — Directions 70B dated 28 April 2022 issued by the Indian Computer Emergency Response Team (CERT-In), Ministry of Electronics & Information Technology (MeitY). The following mandatory obligations are fulfilled:
Cyber Incident Reporting
Mandatory reporting of 20 specified types of cyber security incidents to CERT-In within 6 hours of detection/notification, as per the CERT-In Directions 70B (2022).
Log Retention — 180 Days
All ICT system logs (server logs, access logs, authentication logs, network logs) are retained in India for a minimum of 180 days rolling, as mandated. Logs are stored on Indian-jurisdiction servers.
NTP Clock Synchronisation
All ICT infrastructure is synchronised with the National Informatics Centre (NIC) NTP server (time.gov.in) or STQC-approved NTP source, as required by CERT-In Directions.
Subscriber / Customer Data — 5 Years
Customer registration information, KYC records, IP address logs, and transaction records of Indian subscribers are retained for a minimum of 5 years as required under CERT-In Directions 70B.
Designated Point of Contact
A designated officer has been appointed as HostupCloud's point of contact with CERT-In for receipt and processing of directions, orders, and incident reports.
VPN & Cloud Provider Obligations
As a cloud service provider and VPN-adjacent operator, HostupCloud maintains validated customer names, addresses, contact numbers, email IDs, IP addresses, subscription details, and purpose of service for all subscribers, per Directions 70B.
Customer Obligations under CERT-In
Questions about these policies?
For policy clarifications, abuse reports, or compliance enquiries, contact the relevant team below.