Security & Account Policy
VisiHost provides secure infrastructure, but the security of your specific account and applications relies heavily on your practices.
1. Account Credentials
You are responsible for maintaining the confidentiality of your passwords.
- We strongly recommend enabling Two-Factor Authentication (2FA) in both the Client Billing Area and the Game/Server Control Panel.
- Do not reuse passwords across multiple platforms.
2. Unauthorized Access
VisiHost is not responsible for data loss, service hijacking, or abuse if a malicious actor gains access to your account due to:
- Weak or compromised passwords.
- Phishing attacks directed at you.
- Sharing your panel credentials or API keys with untrusted individuals.
- Malicious plugins or software installed on your server.
If your server is hijacked and used to launch attacks, it will be suspended under our Acceptable Use Policy.
3. Account Recovery
If you lose access to your account, you must complete a strict identity verification process. This may involve verifying the original payment method or providing government-issued ID. We reserve the right to deny account recovery if identity cannot be conclusively proven.
4. API Keys and Tokens
Treat your API keys and Panel access tokens like passwords. Never commit them to public GitHub repositories or share them in public Discord channels. If you suspect a key is compromised, revoke it immediately from the panel settings.