Common Reasons We Cannot Process Sensitive Requests from Unregistered Contacts
Table of Contents
- Service Direction
- Service Transparency
- Main Content Details
- Our Core Commitments
- Security
- Common Mistakes
- Checklist
- Malaysia Acts & Compliance
- Responsibility Breakdown (iCoreHosting & Client)
- Support Information
- FAQ
- Use Case Scenarios
- Summary
- Request Email Template
- Official Company Letter Template
1. Service Direction
This article explains why iCoreHosting cannot process sensitive, high-impact, or security-related actions when requests come from unregistered, unverifiable, or non-authorised contacts. Our priority is to protect client data, prevent identity misuse, and ensure regulatory compliance.
2. Service Transparency
iCoreHosting must verify and authenticate the requester before carrying out actions involving security, data access, service modification, service termination, DNS changes, password resets, internal logs, or financial adjustments. These controls protect both the company and the client.
3. Main Content Details
We cannot proceed with sensitive actions when:
- The requester is not the registered account owner or authorised representative.
- The requester contacts us via a personal number, private WhatsApp, or unknown email.
- No written approval exists in the client’s WHMCS account.
- There is insufficient documentation to validate identity.
- The requester attempts to bypass standard procedures.
- The task involves legally sensitive information such as logs, personal data, billing, or server access.
4. Our Core Commitments
- Reliability – Every request must come from verified sources.
- Availability – Support is ready, but only for authorised users.
- Accountability – All actions are logged for audit and compliance.
- Scalability – A unified verification process keeps operations stable.
- Security – Identity verification is mandatory for all sensitive actions.
- Agility – Faster processing for verified contacts.
5. Security
- We must verify the requester before accessing or modifying services.
- Unverified instructions cannot be executed under any condition.
- Requests must come from the registered email or WHMCS login.
- WhatsApp numbers must match the registered contact list.
- Company-level actions require official documentation.
6. Common Mistakes
- Asking for password resets from personal WhatsApp.
- Requesting server access from unlisted staff.
- Using a general company email without verification.
- Providing screenshot approvals instead of official requests.
- No documented authorisation during staff resignation.
7. Checklist
- Is the requester listed in WHMCS contacts?
- Is the email originating from the registered domain?
- Is there a valid company letter?
- Is the action sensitive or high-impact?
- Is PDPA compliance required?
8. Malaysia Acts & Compliance
iCoreHosting follows Malaysian laws:
- Personal Data Protection Act (PDPA) 2010 – Identity verification required before releasing personal or service information.
- Communications and Multimedia Act (CMA) 1998 – Sensitive service actions must follow regulated procedures.
9. Responsibility Breakdown
iCoreHosting Responsibilities:
- Protect client data and systems.
- Follow legal requirements.
- Perform actions only after verification.
Client Responsibilities:
- Maintain updated WHMCS contact list.
- Submit official approval letters when required.
- Ensure proper staff handover procedures.
- Avoid sharing passwords within the organisation.
10. Support Information
Primary Support (Fastest Response)
Email: [email protected]
Secondary Support
Office Phone: 07-2881230
Telegram: t.me/icorehosting
WhatsApp (for non-sensitive enquiries only)
11. FAQ
Q: Why can't you do it first and verify later?
Because sensitive actions without verification violate PDPA and CMA requirements.
Q: Can WhatsApp approval be used?
Only if the number belongs to a registered contact.
Q: What if my staff left the company?
Please submit an official letter to update authorised personnel immediately.
12. Use Case Scenarios
- Unregistered staff asking for server login → Not allowed.
- Finance team requesting invoice deletion without approval → Not allowed.
- Ex-employee requesting DNS changes → Not allowed.
- CEO sending official signed letter → Allowed.
13. Summary
Sensitive requests require identity verification to protect both client and provider. Following proper channels ensures security, compliance, and service accuracy.
14. Request Email Template
Subject: Sensitive Request Authorisation – (Company Name)
Dear iCoreHosting Support Team,
I would like to request the following action for our service:
(Describe the action clearly)
Please proceed and consider this as an official authorisation from our company.
Name:
Position:
Registered Email:
Phone Number:
Thank you.
15. Official Company Request Letter Template
[Company Letterhead]
Date: ____________
To: iCoreHosting Support Department
Subject: Official Authorisation for Sensitive Request
We hereby authorise iCoreHosting to perform the following action for our account:
(Describe the specific request clearly)
This authorisation is approved by:
Name:
Designation:
Company Stamp (if applicable)
Signature:
