Website operator
Tungsto is operated by gpucrypt LLC.
158 LORRAINE LOOPSTATEN ISLAND NY 10309-1521
USA
Shared responsibility
Tungsto protects facilities, network infrastructure and the control plane. Customers protect operating systems, applications, credentials, encryption keys and backups on their servers.
Account controls
Passwords are stored as slow salted verifiers and sessions use hashed random tokens. API keys are shown once, stored as hashes and can be revoked. Sensitive server actions require current authentication and are audit logged.
Infrastructure controls
Administrative access is restricted by role, management networks are separated from customer traffic, and hardware changes are tracked. Baseline DDoS filtering is included, with advanced profiles available.
Data handling
Payment webhooks are signed and idempotent. Ledger entries are append-only. Server media is wiped before return to inventory under the documented termination workflow.
Reporting vulnerabilities
Send a concise report through the security contact form with reproduction steps and impact. Do not access customer data, persist on systems or disrupt service while testing. Good-faith reports receive acknowledgement and coordinated remediation.
Policy contact
Questions can be submitted through the contact page; account-specific requests require separate ownership verification. This document is written for operational clarity and does not waive rights that cannot lawfully be waived.