Security you can check, not just trust
Your server’s security starts before you log in: how the hardware was tested, what happened to the previous tenant’s data, and who can reach the management interface. Here is how we handle each of those.
- NIST 800-88drive sanitisation
- 24 hburn-in before delivery
- 0BMCs on public IPs
- PGPon every email, if you want it
Found a vulnerability?Responsible disclosure
- Contact
- support@dedicrypto.com
- Encryption
- PGP key 57CA57E5623B5067
- Machine-readable
- /.well-known/security.txt
- Acknowledgement
- Within 24 hoursThen updates until it is fixed
- Credit
- Public, if you want it
What we do on every server
Drives wiped before reuseWhen a server is returned, NVMe drives are erased with the drive’s own secure-erase (sanitize) command and hard drives are overwritten and verified, following NIST SP 800-88. A drive that cannot be wiped is destroyed, never reused.
Tested before deliveryEvery machine goes through a 24-hour burn-in, a memory test and SMART checks before it reaches you, and you get the report. Firmware (BIOS and BMC) is updated to the vendor’s current release at the same time.
IPMI kept off the internetManagement controllers sit on an isolated network. You reach the KVM console through the client area over TLS — the BMC is never exposed on a public address, where it would be scanned within minutes.
Accounts that resist takeoverPasswords are hashed with Argon2id, two-factor authentication (TOTP) is available on every account, and new sign-ins trigger an email alert. Support never asks for your password.
Email you can trustAdd your PGP key and everything we send is encrypted to it — invoices, credentials, abuse notices. Our own messages can be verified against our public key.
Minimal data, minimal riskWe do not hold identity documents, payment cards or visitor IP logs, so there is nothing of that kind to leak. The full inventory is in our privacy policy.
Where our job ends and yours begins
A dedicated server gives you full control — which also means the operating system is yours to secure.
We take care of
- Hardware, firmware and spare parts
- Physical access to the racks
- Network, DDoS filtering, IPMI isolation
- Wiping drives between customers
You take care of
- OS updates and firewall rules
- SSH keys and user accounts
- The software you install
- Backups and disk encryption
Security questions
Ask the engineers who run the servers — median first reply under 15 minutes, 24/7.
Contact usCan your staff access my server?
Not without you. We have no credentials on your operating system and we do not keep a backdoor account. Technicians touch the hardware only for repairs, and every intervention is logged in your ticket history.
Should I encrypt my disks?
If your threat model includes physical access to the machine, yes. Full-disk encryption with LUKS and a remote unlock over SSH (dropbear in the initramfs) keeps data unreadable when the server is powered off. Our guide walks you through it.
What happens to a failed drive?
A drive pulled from your server is wiped if it still works, or physically destroyed if it does not. It never leaves the facility in a readable state.
How do I report a vulnerability?
Write to support@dedicrypto.com, ideally encrypted with our PGP key. We acknowledge reports within 24 hours, keep you informed while we fix, and credit you publicly if you wish. Our contact details are also in security.txt.
