DFX CLOUD SOLUTIONS LLC
1209 Mountain Road Pl NE, Ste R
Albuquerque, NM 87110, United States
DFX Legal Center

Security and Incident Management Policy

Shared responsibility, prevention, containment, investigation, and incident recovery.

Version 2.1Updated: July 30, 2026Effective: July 30, 2026
Shared responsibility, prevention, containment, investigation, and incident recovery.

1. Shared responsibility model

DFX secures infrastructure and components expressly managed by DFX. The Customer secures users, endpoints, credentials, content, applications, and configurations under Customer control.

2. Minimum Customer duties

3. No absolute security

Firewalls, WAF, antimalware, CDN, monitoring, encryption, and backups reduce risk but do not eliminate zero-day vulnerabilities, social engineering, human error, provider compromise, or sophisticated attacks.

4. Preventive and emergency measures

DFX may reset compromised credentials, block IP addresses or ports, isolate accounts, disable components, terminate processes, revoke sessions, preserve logs, or restore systems when reasonably necessary.

5. Notice and cooperation

The Customer must report incidents promptly, preserve evidence, and cooperate. Logs or relevant files should not be destroyed before analysis unless immediate containment requires it.

6. Investigation

DFX may review logs, metadata, hashes, files, access activity, and configurations. Technical reports are not by themselves judicial forensic opinions or definitive attribution.

7. Recovery and costs

Malware cleanup, forensic analysis, reinstatement, hardening, intensive monitoring, or out-of-scope assistance may be billed separately.

8. Regulatory notices

The Customer is responsible for determining whether affected individuals, regulators, insurers, or partners must be notified.

9. Providers

DFX may coordinate with data centers, registrars, CDNs, security providers, and other vendors to contain or investigate incidents.