Table of Contents
Service Direction / Introduction / Scope
At iCoreHosting, we take your data privacy seriously. This article outlines our security policy regarding the release of hosting-related information. It explains the strict verification protocols we follow to protect your account and details exactly who is authorized to request sensitive data such as login credentials, DNS records, and email settings.
Service Transparency
To prevent social engineering attacks and unauthorized data breaches, iCoreHosting enforces a "Zero Trust" policy for unverified contacts. We cannot share account details with anyone solely based on their claim to be an employee or contractor. Verification is binary: either the request comes from a registered channel, or a Support PIN is provided.
Definitions
- Registered Email: The primary email address officially listed in your iCoreHosting Client Portal profile.
- Registered Mobile: The phone number associated with your account for SMS or WhatsApp verification.
- Support PIN: A unique security code found in your Client Area, used to verify identity over phone or chat.
- Hosting Information: Sensitive data including passwords, server IP addresses, DNS records, and control panel access.
Description of Content: Authorization Methods
1. Who Can Access Information?
We are authorized to release information ONLY to sources that match one of the following criteria:
- Email: The request is sent from the Registered Email Address.
- Mobile: The request comes from the Registered Mobile Number (via WhatsApp or SMS).
- Support PIN: The requester provides a valid Support PIN (essential for third-party developers or staff not listed on the account).
2. How to Retrieve Your Support PIN
If you are calling in or using Live Chat, you will be asked for this PIN. Here is how to find it:
- Login to the Client Portal: https://billing.icore.com.my/clientarea.php
- Look for the "Support PIN" section on the dashboard (usually top left or under account details).
- Provide this code to the support agent.
Common Mistakes
- Emailing from Personal Accounts: Sending a request from a personal Gmail/Yahoo account instead of the registered company email. We will deny these requests.
- Project Managers Calling from Unregistered Numbers: Even if you are the project lead, if your phone number is not on file and you don't have the Support PIN, we cannot assist you.
- Forgetting to Update Staff Details: Failing to remove old employees from the authorized contact list or failing to update the Support PIN after staff turnover.
Responsibility Breakdown
iCoreHosting Responsibilities:
- Strictly verify every request against the registered database.
- Refuse disclosure of information to unverified parties to protect client data.
Client Responsibilities:
- Keep email and mobile contact information up to date in the billing portal.
- Share the Support PIN only with authorized staff or developers.
- Generate a new Support PIN if you suspect unauthorized access.
Support Information
If you need assistance verifying your account, please use our official channels:
- Support Portal: https://www.icore.com.my/support
- Email: [email protected]
- Telegram: https://t.me/icorehosting
- WhatsApp: https://wa.me/60197429566
- Emergency (After Hours): +60 19-742 9566
FAQ
Q: My web developer needs access, but I don't want to give them my login. What do I do?
A: You can provide them with your Support PIN. This allows them to discuss technical issues with our support team without needing full access to your billing account.
Q: I lost access to my registered email. How can I recover my account?
A: Please contact us via your registered mobile number (WhatsApp/Phone). If both are inaccessible, you may need to go through a manual identity verification process involving official documentation.
Q: Can I add multiple emails to my account?
A: Yes, you can add "Sub-Accounts" or "Contacts" inside the Client Area. This allows other team members to open tickets legally.
Summary
iCoreHosting will only release sensitive hosting data to requests originating from a Registered Email, a Registered Mobile Number, or a caller providing a valid Support PIN. This ensures your data remains secure from unauthorized social engineering attempts.
Use Case
| Scenario | Authorization Status | Outcome |
|---|---|---|
| Client calls from an unknown number but provides the correct Support PIN. | Authorized | Support team assists with the request. |
| Company Manager emails from a personal Gmail address asking for cPanel password. | Unauthorized | Request denied. Client asked to email from registered address. |
| Developer messages via Telegram without a PIN. | Unauthorized | Support declines to share info until PIN is provided. |
