For anyone who wants the specifics under the plain-English summary above:
- Public HTTPS/TLS terminated in front by Nginx Proxy Manager (NPM), with the application kept simple and locked down on a private network.
- Brute-force and abuse protection with fail2ban, rate limiting, and GeoIP filtering to shrink the attack surface.
- Firewall rules, least-privilege access, hardened server configuration, and clear separation between public and private services.
- Application code, dependencies, and the underlying platform are reviewed against known CVEs and common exploit classes, with EPSS-driven prioritization.
- Role-based access control (RBAC), optional two-factor authentication, strong session handling, and protected admin areas.
- Backups for application files and databases, replicated to additional backup servers and validated as part of maintenance.
- Ongoing dependency review, OS/runtime patching, and uptime/health/storage/SSL monitoring.
Compliance: who is responsible for what
Applications are hosted on professionally managed infrastructure with security controls selected for each deployment. Datacenter-level certifications or assurance reports, where applicable, belong to the underlying facility or service provider and do not automatically certify an application. Security, access controls, retention, backups and compliance requirements are evaluated for each project.
- The facility: Surety Data Centers
- Any certifications or audit reports belong to the facility operator that holds them, not to MyAppDone or to an application. Surety’s public website does not list certifications such as SOC reports or ISO 27001, so none are claimed here. MyAppDone does not hold these certifications itself.
- Inherited from the facility
- Physical security, power, cooling, and network connectivity come from Surety. It publishes its facility specifications — including redundant power and cooling, biometric physical security, and on-site staff around the clock — at suretydc.com.
- Implemented by MyAppDone
- The application and server safeguards listed above: HTTPS, hardened servers and firewalls, abuse protection, role-based access and two-factor sign-in, backups, patching, and monitoring.
- Your application’s own requirements
- Rules such as HIPAA or PCI DSS depend on what data the app handles and on your policies. They are not satisfied automatically by where an app is hosted; they are scoped and documented for each project that needs them.