Trust center

Security claims
with clear boundaries.

Vodania documents controls that are active, requirements that must be confirmed per reservation, and assurance work that is not yet claimed.

Active web controls

  • TLS with automatic certificate renewal for Vodania and its payment-portal route.
  • HTTP Strict Transport Security, Content Security Policy, MIME-sniffing protection, frame restrictions, and restrictive browser permissions.
  • Same-origin reservation API, server-side price validation, configuration allowlists, request-size limits, and submission rate limiting.
  • Reservation records are stored outside the public web root with restricted service-account permissions.

Workload controls

Tenant isolation, storage encryption, deletion timing, facility access controls, network segmentation, host logging, backup handling, and incident escalation depend on the allocated provider and node. These controls are not assumed from a marketing page: they must be stated in the reservation confirmation or enterprise order before customer data is uploaded.

Do not upload sensitive data before confirmation

Customers with regulated, confidential, export-controlled, health, financial, or government workloads should request a written control review and any required data-processing agreement first.

Data handling

The public site records business contact details, requested infrastructure configuration, optional SSH public keys, payment reference, and security metadata needed to operate and protect the service. Private keys and payment-card credentials must never be submitted to Vodania forms. Payment credentials are handled by the selected payment provider.

Assurance status

Vodania does not currently claim SOC 2, ISO 27001, PCI DSS service-provider certification, HIPAA eligibility, FedRAMP authorization, or a public compliance attestation. Contract-specific assurance evidence may be requested from the capacity desk. Roadmap statements are not certifications.

Responsible disclosure

Report a suspected vulnerability to admin@cityofhats.com. Include affected URL or service, reproduction steps, impact, and a safe contact method. Do not access other customers' data, disrupt service, or retain data beyond what is necessary to demonstrate the issue.

Machine-readable contact: /.well-known/security.txt