This policy defines customer responsibilities and ServerTurk’s obligations regarding server security, access control, account safety, and data protection.
Customers are fully responsible for:
Server passwords
RDP/SSH port changes
Firewall configuration
Control panel passwords
Script/plugin safety
Game server security
Outdated software
Unauthorized access
Viruses or malware originating from their own devices
ServerTurk is not liable for security issues caused by customer configurations.
Customers must:
Not share their passwords
Use strong and unique passwords
Change default RDP/SSH ports
Use IP whitelisting
Take precautions against brute-force attacks
Any breach caused by weak or shared credentials is the customer's responsibility.
All installed software is under customer responsibility:
Web applications
Game server plugins
CMS systems (WordPress etc.)
Custom software
Modules and extensions
ServerTurk is not responsible for vulnerabilities in customer-uploaded software.
ServerTurk is not responsible for:
Malware from customer devices
Compromised passwords
Keyloggers/stealers
Unauthorized remote access
Infection or exploitation due to unsafe software
ServerTurk ensures datacenter-level physical security, including:
24/7 surveillance
Biometric access control
Power redundancy
On-site security personnel
These measures do not cover software-level server security.
Backups are entirely the customer’s responsibility.
ServerTurk is not obligated to provide:
Lost data
Corrupted files
Recovery after hacks
Recovery after misconfiguration
Even if ServerTurk provides automatic backups, they are not guaranteed.
DDoS protection is limited to available capacity.
Attacks exceeding capacity may lead to:
Connectivity loss
Filtering
Service suspension
ServerTurk is not responsible for these outcomes.
ServerTurk is not responsible for:
Stolen passwords
Shared credentials
Software vulnerabilities
Script/plugin-based hacks
Misconfigured firewall rules
Outdated software
Malware-related data loss
Customer-side security mismanagement
Damages caused by DDoS/attacks
These do not qualify for refunds or compensation.