Our comprehensive approach to protecting your data and ensuring the highest standards of information security across all our services and operations.
ServerToday (Thailand) Co., Ltd. is committed to maintaining the highest standards of information security to protect our clients' data, systems, and infrastructure. This Information Security Policy outlines our comprehensive approach to safeguarding information assets and ensuring business continuity.
Our security framework is built on internationally recognized standards including ISO/IEC 27001:2022 and ISO/IEC 27701:2019, ensuring that we meet and exceed industry best practices for information security management and privacy information management.
Security Certifications
We are certified to ISO/IEC 27001:2022 for Information Security Management and ISO/IEC 27701:2019 for Privacy Information Management, demonstrating our commitment to protecting your data.
ServerToday employs a defense-in-depth security strategy that protects information assets through multiple layers of security controls. Our approach encompasses physical, technical, and administrative safeguards designed to prevent unauthorized access, use, disclosure, disruption, modification, or destruction of information.
Our ISMS is based on ISO/IEC 27001:2022 standards and provides the framework for managing information security risks systematically. The ISMS includes documented policies, procedures, and controls that are regularly reviewed and updated.
Chief Information Security Officer (CISO)
Oversees all information security activities and reports directly to executive management
Security Operations Team
Monitors, detects, and responds to security incidents 24/7
Data Protection Officer (DPO)
Ensures compliance with privacy regulations and manages data protection activities
All Employees
Required to follow security policies and report security concerns immediately
All employees receive mandatory security awareness training upon hiring and annually thereafter. Training covers topics including password security, phishing awareness, social engineering, data handling, and incident reporting.
Privileged accounts with elevated system access are strictly controlled, monitored, and audited. All privileged access sessions are logged and reviewed regularly. Privileged credentials are stored in secure vaults with automated rotation.
Highly Confidential
Data requiring maximum protection (e.g., financial records, authentication credentials)
Confidential
Sensitive business information (e.g., customer data, contracts)
Internal
Internal use only (e.g., policies, procedures)
Public
Information approved for public disclosure
Data is retained according to legal requirements and business needs. When data reaches end-of-life, it is securely destroyed using industry-standard methods including secure erasure for digital media and physical destruction for hardware.
Our Security Operations Center (SOC) provides 24/7/365 monitoring of all systems and networks. We employ Security Information and Event Management (SIEM) systems to detect and respond to security threats in real-time.
Regular vulnerability assessments and penetration testing are conducted by internal teams and third-party security firms. Critical vulnerabilities are patched within 24 hours, high-severity within 7 days, and medium-severity within 30 days.
Our incident response team follows a structured process aligned with ISO/IEC 27035 standards:
If you discover a security vulnerability or incident:
We maintain comprehensive business continuity and disaster recovery plans that are tested annually. Our infrastructure is designed with redundancy to ensure service availability even during adverse events.
ServerToday complies with applicable laws and regulations including:
All third-party vendors and partners are required to meet our security standards. We conduct security assessments before onboarding and regular reviews throughout the relationship. Vendors handling sensitive data must provide evidence of appropriate security controls.
For security-related inquiries, incident reports, or vulnerability disclosures, please contact our security team:
111/128 Moo 2, Ratchaphruek Rd.
Bangraknoi, Mueang District
Nonthaburi 11000, Thailand
Response Time Commitment
Report Security Vulnerabilities
If you discover a security vulnerability, please report it immediately to support@servertoday.com. We take all security reports seriously and will respond promptly.