TildaVPS security posture: how we protect infrastructure, customer data, and the platform.
Last updated: 2026-01-05
We are honest about where we stand. We run GDPR-compliant practices and we do not claim certifications we do not hold.
Servers run on KVM with dedicated resources, always-on DDoS mitigation at the network edge, and restricted access to data centers.
Traffic is encrypted in transit with TLS. Backups are encrypted and stored off-site. Customer data is never sold or used for advertising.
Access to production systems is role-based and limited to what each role needs. Administrative actions are logged and reviewed.
We monitor the network and services continuously. When an incident affects you, we communicate through the status page and your account.
Security researchers are welcome. Report issues to [email protected] or via our security.txt file. We acknowledge valid reports and coordinate fixes.
We are GDPR compliant and publish our data processing terms. We do not hold SOC 2 or ISO 27001 certification at this time; the controls we do run are documented on this page.