Security

How we handle security.

How the platform is protected, where our responsibility ends and yours begins, and what we commit to when a vulnerability affects your stack. Advisories and incidents are published here rather than sent quietly to the people who ask.

Last advisory 2026–05–01 · CVE-2026-31431 · Copy Fail
Responsibility

What we secure,
and what you secure.

A virtual private server is yours to administer. Being clear about the boundary matters more than claiming to cover everything, because the gaps are where incidents happen.

Physical

OursFacility access control, power, cooling and the hardware itself. Our staff are the only people with physical access to machines running customer workloads.

PrivateByte
Hypervisor

OursHost operating system, virtualisation layer and the isolation between one customer’s server and another’s. Patched by us, on our own maintenance windows.

PrivateByte
Network

OursRouting, address space and always-on DDoS protection. We also filter classes of abusive outbound traffic to keep our address reputation clean for everyone on it.

PrivateByte
Guest OS

YoursThe operating system inside your server, its packages and its updates. We will always tell you when a CVE affects it; applying the fix is yours.

Customer
Applications

YoursAnything you install and anything it exposes. We do not inspect or police what you run beyond the acceptable use policy.

Customer
Access

SharedWe secure the control panel and account authentication. You are responsible for your SSH keys, your passwords and who you share them with.

Shared
Platform

How the platform
is protected.

Isolation
Pertenant
Between customers

Each server runs in its own virtualised environment with its own storage and its own network attachment. No shared filesystem and no shared address.

Access
2FA
On accounts and staff

Available on every customer account and required for administrative access. Administrative actions against customer services are logged.

Data
Yours
We do not read it

We do not inspect the contents of your server or your traffic. We hold what billing requires and what you give us in a support ticket.

Recovery
Daily
Backups and snapshots

Automated daily backups with seven-day retention on every plan, plus snapshots you take yourself before a risky change.

We are a UK company and handle personal data under UK GDPR · breaches affecting personal data are reported to the ICO within the statutory window, as in April 2026

Service-level commitments

When a vulnerability
affects you.

For every customer running on PrivateByte infrastructure, including self-managed VPS, these are the commitments we hold ourselves to when a CVE lands affecting your stack.

01 · Notification
≤24h
CVE notification

From disclosure to a published advisory and notice to affected customers. Critical-severity advisories go out faster.

02 · Patch
≤48h
Critical patch deploy

For software we operate — host OS, networking, the portal. Customer-managed software stays yours, but we always tell you a CVE exists.

03 · Log
Live
Public advisory log

Every notification we send also lives on this page, indefinitely. Including upstream CVEs we track even when we are unaffected.

04 · Disclosure
≤24h
Disclosure response

Found something in PrivateByte itself? You get a human reply within a business day. No bug-bounty platform in between.

Subscribe

How notifications
reach you.

The advisory log above is the canonical record, and the Telegram channel carries every advisory as it is published. Where an advisory needs you to act, we contact affected customers directly. Security contact is separate from marketing email and is not subject to marketing opt-out — your server being exploitable is not a promotional matter.

Email

Account emailUsed when an advisory needs action from you, rather than for everything we publish.

Your account email
Portal

In-app bannerPersistent across the platform whenever your account is affected.

my.privatebyte.com
Telegram

Public channelAdvisories pinned to the channel. No marketing.

@privatebyte
Advisory log

Everything we have sent,
kept where you can read it.

Every advisory we have sent customers, plus upstream CVEs we track even when our infrastructure is unaffected.

2026 · 05 · 01Mitigated
CVE-2026-31431 — “Copy Fail” local privilege escalation

A Linux kernel bug in a userspace crypto interface lets an unprivileged local user escalate to root. We acted inside our 24-hour notification commitment.

Hypervisor hosts, where customer VMs run: module-load blacklist applied. The vulnerable code path is blocked, with zero downtime and no customer impact.

Portal hosts, where the customer panel runs: the affected component is compiled into the kernel rather than loadable as a module, so the modprobe fix does not apply. Only authorised administrators hold shell access there, which contains the local-escalation surface. Rebooted into the patched kernel during an announced window, inside the 48-hour commitment.

Customer VPS guests run their own kernels. If you are on a recent Linux, update and reboot once your distribution ships a patched kernel.

2026 · 04 · 29Unaffected
CVE-2026-41940 — cPanel authentication bypass

We do not run cPanel for the customer platform, so nothing of ours is exposed. If you run cPanel yourself on a VPS with us, patch through cPanel’s release channel — and we are glad to help if you want a hand.

2026 · 04 · 22Patched
Portal account-identifier confusion

An identifier-mapping bug in our billing backend meant a minority of accounts could briefly see another customer’s services during a session. Caught and patched the same day, ICO Article 33 notification filed inside the statutory window, and a regression test pinned in CI so it cannot recur silently. Full write-up available on request.

Responsible disclosure

Found something?
Tell us directly.

Send it to [email protected]. You get a human reply within one business day — not an autoresponder, and not a bug-bounty platform that sits between you and the people who can fix it.

We will not threaten legal action against anyone who reports a vulnerability in good faith, gives us reasonable time to fix it, and does not access or alter customer data while proving it. If you want your name on the advisory, ask and it goes on.

Encrypt it if you want to

Reports are welcome in plain text, but if a finding is sensitive enough that you would rather it never crossed a mail server in the clear, encrypt it to the key below. Verify the fingerprint out of band before you trust it.

2405 7456 18C8 5DE8 1DFD  441E 3169 3B22 5A75 0E20
Public key — [email protected]
-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEany54hYJKwYBBAHaRw8BAQdAWsdZIuY3BIXQjsD5Pvo4dcSH0m/uLUULWPz0
VBlAn/60L1ByaXZhdGVCeXRlIFNlY3VyaXR5IDxzZWN1cml0eUBwcml2YXRlYnl0
ZS5jb20+iJoEExYKAEIWIQQkBXRWGMhd6B39RB4xaTsiWnUOIAUCany54gIbAwUJ
A8JnAAULCQgHAgMiAgEGFQoJCAsCBBYCAwECHgcCF4AACgkQMWk7Ilp1DiCBaQD+
KDgc4r2r+icgJP1fArgtNeu2UhV1zj6LSWctnGWfjjgA/AuXvg3TePRtJ+Zj2y4m
Innqbi9Jjtk82USvAxGDIh4AuDgEany54hIKKwYBBAGXVQEFAQEHQPAya1rNqBEp
vShIvnUqwsygi+rBn3KzcsiJD4Lfgik9AwEIB4h+BBgWCgAmFiEEJAV0VhjIXegd
/UQeMWk7Ilp1DiAFAmp8ueICGwwFCQPCZwAACgkQMWk7Ilp1DiD4owD9ESTHC8JM
jiJUP1L737BBJWMs8wP6xFJzGN5fjEHeMUQBAJ6ErARQvm/krazSMsSTVvjD1Wjg
KZolW30EtEbKHEcL
=n6KZ
-----END PGP PUBLIC KEY BLOCK-----

Median first reply under an hour · no bug-bounty middleware