Security and Cybersecurity

Service legal standards — Security – vWAF – Firewall – Anti-DDoS – SOC – Threat Intelligence

Documentation codeTCPL-18
Version1.0
Effective date18/08/2026
Review date18/08/2027
Department in chargeLegal

PART I - PURPOSE AND SCOPE

1.1. This legal standard (“Documentation”) sets forth the standard terms and conditions applicable to the provision and use of the Security service group, comprising vWAF, Firewall, Anti-DDoS, SOC, and Threat Intelligence (“Service”), provided by Pho Tue SoftWare Solutions JSC (“HiTechCloud”) to customers (“Customer”).

1.2. The Documentation applies to all Contracts, Orders, Appendices, or electronic service order confirmations referencing this Documentation. In case of conflict, separate commercial Terms signed between the two Parties shall take precedence, followed by this Documentation, and the policies published at https://hitechcloud.vn/tai-lieu-ho-tro/.

1.3. The Service scope includes web application firewalls (vWAF), infrastructure firewalls, Anti-DDoS protection, Security Operations Center (SOC) incident monitoring and response, and Threat intelligence bulletins.

Part II – Definitions

2.1. “vWAF” is a virtualized Web application firewall that filters HTTP/HTTPS Traffic according to a protection ruleset.

2.2. “Anti-DDoS” is a solution for detecting and mitigating distributed denial-of-service attacks at the network layer and application layer.

2.3. “SOC” is a shift-based security operations center that performs monitoring, triage, and security incident response.

2.4. “P1 Incident” is the most severe security incident according to the published classification table, posing a risk of directly affecting the Customer's operations or data.

2.5. “Vulnerability” is a technical weakness in the Customer’s system detected and Alerted during the provision of the Service.

Part III – Service description and configuration

3.1. The service is provided under a subscription model, and the Monitoring scope (IP ranges, Domain, applications, log sources) is finalized in the technical Appendix; scope changes must be confirmed in writing or via the Admin portal.

3.2. SOC provides 24/7 monitoring for service plans with corresponding commitments; the incident response process, emergency communication channels, and contact list of both Parties are established upon Service initialization.

3.3. The vWAF/Firewall rule set is updated periodically; learning mode may be applied in the initial phase to reduce false positives.

Part IV – SLA and compensation

4.1. For P1 Incidents, HiTechCloud commits to issuing an alert to the Customer's point of contact within 15 (fifteen) minutes from the time the system records and confirms the event; the final resolution time depends on the nature of the incident and the Customer's coordination.

4.2. The Customer understands and agrees that the Security service by its nature mitigates risk, rather than providing an absolute guarantee of exclusion; no solution can prevent all attacks, and the occurrence of a security incident does not automatically constitute a violation of HiTechCloud's obligations if HiTechCloud has properly executed the committed procedures.

4.3. The sole remedy when HiTechCloud violates the SLA is a fee deduction in the subsequent billing cycle according to the published deduction schedule; the Customer has no right to request a cash refund or any other form of compensation for SLA violations.

4.4. HiTechCloud's total indemnity arising from or related to the Service shall under no circumstances exceed the total fees paid by the Customer for the most recent service cycle; HiTechCloud is not liable for indirect, consequential damages, lost profits, business opportunities, lost data, or reputational damage.

4.5. Planned maintenance is notified at least 48 (forty-eight) hours in advance via Email or the management portal; planned maintenance duration, force majeure events, and interruptions due to Customer fault are not counted as SLA violation time.

PART V - FEES AND PAYMENT

5.1. The Customer shall make advance Payment of 100% of the service cycle value within 03 (three) working days from the date HiTechCloud Releases the fee notice or Invoice, unless otherwise stipulated by a separate Contract.

5.2. Overdue payment amounts are subject to a late payment interest rate of 0.05%/day calculated on the overdue amount, from the overdue date until the actual payment date.

5.3. HiTechCloud reserves the right to suspend the Service after 07 (seven) days of late payment and execute Service termination after 15 (fifteen) days of late payment without compensation; the Customer remains under obligation to pay all fees incurred up to the termination date.

PART VI – RIGHTS AND OBLIGATIONS OF THE PARTIES

6.1. The Customer has the Obligation to remediate Vulnerabilities Alerted by HiTechCloud within the recommended timeframe; HiTechCloud is not liable for damages arising from Alerted Vulnerabilities that the Customer fails to remediate.

6.2. The Customer provides access permissions, logs, and necessary system information within the scope of monitoring; withholding information correspondingly limits HiTechCloud's liability.

6.3. HiTechCloud has the Obligation to operate in accordance with published procedures, maintain the Information security of the Customer's systems, and act only within the scope of Delegation.

Part VII – Acceptable use and prohibited conduct

7.1. Security reports, assessment results, and Threat intelligence bulletins are solely for the Customer's internal use; publishing, sharing with any Third party, or using them to attack any system is prohibited.

7.2. It is prohibited to use the Service infrastructure to perform scanning, probing, or attacking systems not owned by or without valid Delegation to the Customer.

7.3. The Customer shall not use the Service to violate Vietnamese law, infringe upon national security, distribute malware, attack third-party systems, or infringe upon the intellectual property rights or personal data of any organization or individual; HiTechCloud reserves the right to immediately suspend services upon detecting a violation.

Part VIII – Security and personal data

8.1. Each Party undertakes to maintain the Information security of the other Party's non-public information obtained during the provision and use of the Service, and to use it solely for the purpose of Service performance; the confidentiality Obligation shall survive for 03 (three) years after Service termination, unless otherwise required by Law or a competent State authority.

8.2. Personal data processing complies with the Law on Personal Data Protection No. 91/2025/QH15 (Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15) and Decree No. 356/2025/NĐ-CP (Nghị định số 356/2025/NĐ-CP) detailing a number of Articles of the Law on Personal Data Protection; HiTechCloud only processes Personal data pursuant to lawful instructions from the Customer, applies appropriate technical and organizational measures, and notifies the Customer upon detecting an Incident of Personal data disclosure or loss in accordance with legal regulations.

8.3. Security Logs may contain Personal data; both Parties shall process them under the principle of data minimization and solely for system security purposes in accordance with the Law on Personal Data Protection No. 91/2025/QH15 (Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15) and Decree No. 356/2025/ND-CP (Nghị định số 356/2025/NĐ-CP).

PART IX – SUSPENSION AND TERMINATION

9.1. HiTechCloud reserves the right to suspend part or all of the Service when: (i) the Customer is overdue on Payment by more than 07 (seven) days; (ii) the Customer violates the acceptable use Regulation; (iii) requested by a competent State authority; or (iv) necessary to prevent system security risks.

9.2. Each Party has the right to effect Service termination if the other Party commits a Violation of a fundamental Obligation and fails to remedy it within 15 (fifteen) days from the date of receiving written Notification; HiTechCloud has the right to terminate after 15 (fifteen) days from the date the Customer is suspended due to late Payment without making full Payment.

9.3. Within 07 (seven) days from the date of Service termination, the Customer will be supported in exporting data in common formats; upon expiration of this period, all Customer data will be permanently Deleted from the system and cannot be Restored, and HiTechCloud has no Obligation for further retention.

PART X – VALIDITY AND APPLICABLE LAW

10.1. This Documentation is an integral part of the Service Agreement and the policies published at https://hitechcloud.vn/tai-lieu-ho-tro/; the Customer registering, making payment, or continuing to use the Service constitutes acceptance of the entire Documentation.

10.2. This Documentation and related contracts, appendices, and electronic confirmations may be signed using digital signatures pursuant to the Law on Electronic Transactions No. 20/2023/QH15 (Luật Giao dịch điện tử số 20/2023/QH15) and Decree No. 23/2025/NĐ-CP on electronic signatures and trust services (Nghị định số 23/2025/NĐ-CP), holding legal validity equivalent to paper documents with direct signatures and seals.

10.3. The Documentation is governed by Vietnamese law. All disputes shall first be resolved through negotiation and mediation within 30 (thirty) days; if unsuccessful, the dispute shall be submitted to the competent People's Court in Ho Chi Minh City for resolution.

Documentation issued by HiTechCloud and subject to amendment with 30-day prior notification on https://hitechcloud.vn/tai-lieu-ho-tro/.

Revision history

Current version (v1.0)by
Updatedby HiTechCloud
Follow category: Security and CybersecurityGet notified when new documents are added to this category.

If this article did not answer your question, please contact HiTechCloud for help.

Contact