The Diversity Resources web server is hosted at Siteground.
Siteground is a leading hosting provider and provides the following security features:
- Employs the latest PHP 7 version with the latest security fixes
- Runs Apache in a chrooted environment with suExec
- Sophisticated IDS/IPS systems which block malicious bots and attackers (intrusion detection/prevention systems)
- Uses a custom-built in-house nginx security module that scans incoming requests and protects our customers from the most common attacks
- ModSecurity is installed and security rules are updated weekly, protecting from the most common attacks
- Maintains all software providing database services (FTP, SMTP, IMAP/ POP3, HTTP, HTTPS) up to date with latest security patches
- Constantly monitors for vulnerabilities in the most popular applications and modules, and whenever possible develops virtual patches in the form of WAF rules (Web application firewall)
- Ensures that users’ data is accessed only by trusted personal on request by following strict policies and keep detailed records for such access
We conduct third-party penetration testing (PEN tests) annually.
Diversity Resources also subscribes to Sucuri, providing these additional security features:
Malware & Hack Protection
- Intrusion Prevention System (IPS)
- Blocking bad bots and automated attacks
DDoS Attack Mitigation
- Deflect DDoS traffic in the outer layers
- Secure bandwidth during attacks
- Stop Volume Based & Protocol Attacks
- Stop Application Attacks (layer 7)
Zero-Day Exploit Prevention
- Vulnerability Scanning
- Patch Management
- Input & Data Validation
- Application Profiling
Brute Force Attack Protection
- Prevent Bot attacks
- Limit logins to a specific IP address or range
FAQs
We don’t collect or analyze customer data beyond contact details (name, email, phone number), which is limited to CMS administrators as needed. This can involve as few as one staff member.
Our application to server requests uses SSL. We encrypt passwords for calendar admin users and conduct annual third-party penetration tests.
We store minimal contact information in our CMS, limited to the necessary number of CMS administrators. Admin passwords are encrypted in our database.
We conduct thorough background checks and enforce policies for customer data confidentiality. We only store CMS administrator contact details (name, email) provided by customers. We do not save any payment information in our database.
We perform annual penetration tests and daily vulnerability scans through our hosting and firewall vendors.
Our products do not collect data, as we only provide an external link to a web-based calendar.
We don’t collect or store sensitive customer data, only the email addresses of calendar administrators, using SSL for transmission security. Admin passwords are encrypted.
We do not sell or distribute any customer data.

