To keep a VPS secure, follow these recommendations at minimum:
- Change SSH port from 22.
- Set up fail2ban.
- Add a passphrase to your SSH key.
- Avoid exposing ports; use a tunnel like Cloudflare.
- Configure a firewall.
- Disable root login.
- Update regularly.
when user request to delete a data, it must be permanently removed, or at least follow a strict retention window before erasure.
Too many companies hoard "deleted" data indefinitely.
Privacy and security must be a mindset, not an afterthought.
It took a massive effort to ensure this wasn't the case for Basecamp and HEY. Especially when it comes to deleting log files, database backups, and all the other auxiliary copies of your stuff that most companies just hang onto until the sun burns out.