1. Shared responsibility model
DFX secures infrastructure and components expressly managed by DFX. The Customer secures users, endpoints, credentials, content, applications, and configurations under Customer control.
2. Minimum Customer duties
- Strong unique passwords and MFA.
- Timely updates for operating systems, CMS, plugins, themes, and libraries.
- Licensed software only.
- Least-privilege access and user reviews.
- Protected devices and networks.
- Immediate reporting of suspicious access or phishing.
3. No absolute security
Firewalls, WAF, antimalware, CDN, monitoring, encryption, and backups reduce risk but do not eliminate zero-day vulnerabilities, social engineering, human error, provider compromise, or sophisticated attacks.
4. Preventive and emergency measures
DFX may reset compromised credentials, block IP addresses or ports, isolate accounts, disable components, terminate processes, revoke sessions, preserve logs, or restore systems when reasonably necessary.
5. Notice and cooperation
The Customer must report incidents promptly, preserve evidence, and cooperate. Logs or relevant files should not be destroyed before analysis unless immediate containment requires it.
6. Investigation
DFX may review logs, metadata, hashes, files, access activity, and configurations. Technical reports are not by themselves judicial forensic opinions or definitive attribution.
7. Recovery and costs
Malware cleanup, forensic analysis, reinstatement, hardening, intensive monitoring, or out-of-scope assistance may be billed separately.
8. Regulatory notices
The Customer is responsible for determining whether affected individuals, regulators, insurers, or partners must be notified.
9. Providers
DFX may coordinate with data centers, registrars, CDNs, security providers, and other vendors to contain or investigate incidents.