Service status & availability Crypto-only billing · No-KYC signup

Draft service policy

Security Policy

Draft for operator and legal review before publication or accepting orders. Confirm service commitments and applicable terms.

Website operator

Tungsto is operated by gpucrypt LLC.

Shared responsibility

Tungsto protects facilities, network infrastructure and the control plane. Customers protect operating systems, applications, credentials, encryption keys and backups on their servers.

Account controls

Passwords are stored as slow salted verifiers and sessions use hashed random tokens. API keys are shown once, stored as hashes and can be revoked. Sensitive server actions require current authentication and are audit logged.

Infrastructure controls

Administrative access is restricted by role, management networks are separated from customer traffic, and hardware changes are tracked. Baseline DDoS filtering is included, with advanced profiles available.

Data handling

Payment webhooks are signed and idempotent. Ledger entries are append-only. Server media is wiped before return to inventory under the documented termination workflow.

Reporting vulnerabilities

Send a concise report through the security contact form with reproduction steps and impact. Do not access customer data, persist on systems or disrupt service while testing. Good-faith reports receive acknowledgement and coordinated remediation.

Policy contact

Questions can be submitted through the contact page; account-specific requests require separate ownership verification. This document is written for operational clarity and does not waive rights that cannot lawfully be waived.