1. Scope
This Security Policy applies to VPS and dedicated server services provided by Greenhill Technologies Inc., doing business as NYCServers and NewYorkCityServers ("NYCServers," "we," "us," or "our"). It explains the division of security responsibilities between NYCServers and our customers and how we handle security incidents affecting services.
Our services are unmanaged. Infrastructure protection and occasional support assistance do not make a service managed or create an ongoing obligation to monitor, patch, update, or administer software inside a customer's service.
2. NYCServers' Infrastructure Responsibilities
NYCServers is responsible for maintaining and securing the provider-controlled infrastructure used to deliver our services. We take proactive measures to apply security updates and patches to that infrastructure. This includes physical server hardware, host systems used to provide VPS services, and network infrastructure under our control.
We may perform protective maintenance or restrict an affected service when necessary to protect our infrastructure or other customers, as described in this policy and our Maintenance Policy.
Infrastructure-level protection does not replace security measures inside your service. We do not guarantee that a service will be free from attacks, vulnerabilities, unauthorized access, or compromise.
3. Customer Responsibilities
You are responsible for the operating system and software inside your VPS or dedicated server, including:
- Installing security updates and patches for the operating system, applications, and other software.
- Configuring and securing remote access, firewalls, accounts, permissions, and any software you install or expose to a network.
- Protecting account, administrator, application, and trading credentials and controlling who can access your service.
- Monitoring your environment for suspicious activity and promptly reporting suspected unauthorized access or compromise.
- Maintaining your own backups and managing application configuration, credential changes, and data recovery after an incident or interruption.
NYCServers does not proactively monitor, patch, or update software inside your service. Software-level investigation, malware removal, forensic analysis, and cleanup are not included in the unmanaged service unless separately agreed. Any purchased backup service remains governed by its existing terms.
4. Reporting A Security Concern
Notify us immediately if you suspect unauthorized use of your customer account or a security compromise affecting your service. Open a support ticket through the customer portal or email support@newyorkcityservers.com.
Include the affected service identifier or IP address, when you noticed the issue, and a description of the activity. Do not include passwords, private keys, or trading-account credentials in an initial report. If you cannot access the customer portal, use the support email address.
We do not promise a fixed response, investigation, or resolution time for security reports. This does not limit any notification obligation under our Privacy Policy or applicable law.
5. Protective Action And Customer Notification
When necessary to protect our infrastructure or other customers from a security incident, we may immediately isolate, suspend, or disconnect an affected service without individual customer approval. This may occur where there is a reasonable indication that a service is compromised or presents a security threat. Under Section 5.3 of our Terms of Service, we may also null route an affected IP address or temporarily suspend a service targeted by a DDoS attack. Null routing prevents traffic from reaching the affected IP address.
Protective action may interrupt remote access, applications, or trading activity. We will notify the affected customer at their registered email address as soon as reasonably practicable. Immediate containment may take priority over notification. We will explain the action taken and any remediation required based on the information then available.
Isolation is a protective measure, not a determination that the customer intentionally caused the incident. It does not mean that NYCServers has investigated or cleaned the operating system or software inside the service.
6. Support Access
Assistance requiring access inside your operating system requires your authorization. Infrastructure-level maintenance, isolation, or disconnection under these policies does not require separate customer approval.
Any assistance we agree to provide is limited to the agreed scope. An instance of support assistance does not create an ongoing obligation to monitor, patch, update, or manage the service and does not transfer your security responsibilities to NYCServers.
Authorization for support access is not, by itself, authorization for a destructive reinstall. Reinstallation is addressed in Section 7.
7. Remediation, Reinstallation, And Restoration
Security compromises are assessed case by case. Before reconnecting a service suspended for a compromise, we may require you to address the issue and provide reasonable evidence of remediation. Appropriate steps depend on the incident and may include removing malicious software, correcting an exposed configuration, applying updates, or replacing compromised credentials.
We may require a clean operating-system reinstall when the compromise cannot reasonably be resolved otherwise. We will obtain your explicit authorization before performing a destructive reinstall. A reinstall can erase the service's existing operating system, software, settings, and data. You are responsible for considering the data impact and your available backups before authorizing it.
A service may remain isolated if you decline remediation required for safe reconnection. Agreeing to a reinstall does not guarantee that prior data or applications can be recovered. You remain responsible for restoring and configuring applications, changing affected credentials, and managing data recovery. Requests involving a purchased backup service remain governed by Section 7 of our Terms of Service.
Restoration of connectivity does not certify that your system is secure or free from compromise. No fixed security investigation or remediation deadline is promised. These provisions concern incident handling and do not change the separate cancellation, termination, or data-deletion terms in the Terms of Service.
8. Personal Information And Breach Notifications
A compromise of a customer-managed VPS or dedicated server is distinct from a breach of personal information held by NYCServers, although an incident may involve both. Our Privacy Policy governs our handling of personal information and related breach notifications.
In the event of a data breach affecting your personal information, we will notify affected users without undue delay and in accordance with applicable law, as stated in our Privacy Policy. The unmanaged nature of our services does not remove our obligations concerning personal information we hold. General incident-notification wording in this policy does not replace or delay a notification required by applicable law.