Each server runs in its own virtualised environment with its own storage and its own network attachment. No shared filesystem and no shared address.
How the platform is protected, where our responsibility ends and yours begins, and what we commit to when a vulnerability affects your stack. Advisories and incidents are published here rather than sent quietly to the people who ask.
Last advisory 2026–05–01 · CVE-2026-31431 · Copy FailA virtual private server is yours to administer. Being clear about the boundary matters more than claiming to cover everything, because the gaps are where incidents happen.
OursFacility access control, power, cooling and the hardware itself. Our staff are the only people with physical access to machines running customer workloads.
PrivateByteOursHost operating system, virtualisation layer and the isolation between one customer’s server and another’s. Patched by us, on our own maintenance windows.
PrivateByteOursRouting, address space and always-on DDoS protection. We also filter classes of abusive outbound traffic to keep our address reputation clean for everyone on it.
PrivateByteYoursThe operating system inside your server, its packages and its updates. We will always tell you when a CVE affects it; applying the fix is yours.
CustomerYoursAnything you install and anything it exposes. We do not inspect or police what you run beyond the acceptable use policy.
CustomerSharedWe secure the control panel and account authentication. You are responsible for your SSH keys, your passwords and who you share them with.
SharedEach server runs in its own virtualised environment with its own storage and its own network attachment. No shared filesystem and no shared address.
Available on every customer account and required for administrative access. Administrative actions against customer services are logged.
We do not inspect the contents of your server or your traffic. We hold what billing requires and what you give us in a support ticket.
Automated daily backups with seven-day retention on every plan, plus snapshots you take yourself before a risky change.
We are a UK company and handle personal data under UK GDPR · breaches affecting personal data are reported to the ICO within the statutory window, as in April 2026
For every customer running on PrivateByte infrastructure, including self-managed VPS, these are the commitments we hold ourselves to when a CVE lands affecting your stack.
From disclosure to a published advisory and notice to affected customers. Critical-severity advisories go out faster.
For software we operate — host OS, networking, the portal. Customer-managed software stays yours, but we always tell you a CVE exists.
Every notification we send also lives on this page, indefinitely. Including upstream CVEs we track even when we are unaffected.
Found something in PrivateByte itself? You get a human reply within a business day. No bug-bounty platform in between.
The advisory log above is the canonical record, and the Telegram channel carries every advisory as it is published. Where an advisory needs you to act, we contact affected customers directly. Security contact is separate from marketing email and is not subject to marketing opt-out — your server being exploitable is not a promotional matter.
Account emailUsed when an advisory needs action from you, rather than for everything we publish.
Your account emailIn-app bannerPersistent across the platform whenever your account is affected.
my.privatebyte.comPublic channelAdvisories pinned to the channel. No marketing.
@privatebyteEvery advisory we have sent customers, plus upstream CVEs we track even when our infrastructure is unaffected.
A Linux kernel bug in a userspace crypto interface lets an unprivileged local user escalate to root. We acted inside our 24-hour notification commitment.
Hypervisor hosts, where customer VMs run: module-load blacklist applied. The vulnerable code path is blocked, with zero downtime and no customer impact.
Portal hosts, where the customer panel runs: the affected component is compiled into the kernel rather than loadable as a module, so the modprobe fix does not apply. Only authorised administrators hold shell access there, which contains the local-escalation surface. Rebooted into the patched kernel during an announced window, inside the 48-hour commitment.
Customer VPS guests run their own kernels. If you are on a recent Linux, update and reboot once your distribution ships a patched kernel.
We do not run cPanel for the customer platform, so nothing of ours is exposed. If you run cPanel yourself on a VPS with us, patch through cPanel’s release channel — and we are glad to help if you want a hand.
An identifier-mapping bug in our billing backend meant a minority of accounts could briefly see another customer’s services during a session. Caught and patched the same day, ICO Article 33 notification filed inside the statutory window, and a regression test pinned in CI so it cannot recur silently. Full write-up available on request.
Send it to [email protected]. You get a human reply within one business day — not an autoresponder, and not a bug-bounty platform that sits between you and the people who can fix it.
We will not threaten legal action against anyone who reports a vulnerability in good faith, gives us reasonable time to fix it, and does not access or alter customer data while proving it. If you want your name on the advisory, ask and it goes on.
Reports are welcome in plain text, but if a finding is sensitive enough that you would rather it never crossed a mail server in the clear, encrypt it to the key below. Verify the fingerprint out of band before you trust it.
-----BEGIN PGP PUBLIC KEY BLOCK----- mDMEany54hYJKwYBBAHaRw8BAQdAWsdZIuY3BIXQjsD5Pvo4dcSH0m/uLUULWPz0 VBlAn/60L1ByaXZhdGVCeXRlIFNlY3VyaXR5IDxzZWN1cml0eUBwcml2YXRlYnl0 ZS5jb20+iJoEExYKAEIWIQQkBXRWGMhd6B39RB4xaTsiWnUOIAUCany54gIbAwUJ A8JnAAULCQgHAgMiAgEGFQoJCAsCBBYCAwECHgcCF4AACgkQMWk7Ilp1DiCBaQD+ KDgc4r2r+icgJP1fArgtNeu2UhV1zj6LSWctnGWfjjgA/AuXvg3TePRtJ+Zj2y4m Innqbi9Jjtk82USvAxGDIh4AuDgEany54hIKKwYBBAGXVQEFAQEHQPAya1rNqBEp vShIvnUqwsygi+rBn3KzcsiJD4Lfgik9AwEIB4h+BBgWCgAmFiEEJAV0VhjIXegd /UQeMWk7Ilp1DiAFAmp8ueICGwwFCQPCZwAACgkQMWk7Ilp1DiD4owD9ESTHC8JM jiJUP1L737BBJWMs8wP6xFJzGN5fjEHeMUQBAJ6ErARQvm/krazSMsSTVvjD1Wjg KZolW30EtEbKHEcL =n6KZ -----END PGP PUBLIC KEY BLOCK-----
Median first reply under an hour · no bug-bounty middleware