Summary
- The exact company concerned is Công ty TNHH Phần mềm iNET, tax code 0103581701, registered in Hanoi on 11 March 2009. VNNIC currently identifies this legal name as an official ‘.vn’ registrar, while ICANN lists ‘iNET SOFTWARE COMPANY LIMITED’ under IANA number 3234. Historical references to Công ty Cổ phần INET and other network members labelled iNET should not be silently merged into the same legal entity.
- iNET's commercial strength lies in the sequence, not in a single product: AI-assisted domain discovery, online registration, DNS and account administration, hosting, email, cloud servers, migration support, affiliate acquisition, and white-label reseller tools. Each additional service can make the original registrar account operationally more significant.
- The public terms significantly reduce the core promise. The SLA guarantees 99.9% monthly uptime for hosting, email and cloud services, but compensation is additional service time, exclusions are broad, cloud backup is the customer's responsibility, and the general liability cap is ten times the price of the purchased package, capped at 50 million VND.
- Public network records support the existence of an operational network footprint, not its quality or ownership. AS149068 is associated with the exact directory label and has been observed originating an IPv4 /22 and an IPv6 /48, but these records do not establish data centre ownership, capacity, redundancy, customer count, or the location of a particular workload.
- A serious buyer should test domain transfer, account recovery, backup restoration, data location disclosure, and incident escalation before consolidating services. The cheapest registration price is economically minor compared to the cost of recovering a lost name, rebuilding email reputation, moving a website under time pressure, or discovering that an ‘unlimited’ service has operational limits not captured on the sales page.
The small purchase that owns the front door
A domain registration looks like one of the least consequential technology purchases a small business can make. The price is visible, the product name is familiar, and the transaction can take less time than ordering office supplies. iNET's current site reinforces this impression. Itsdomain showcaseadvertises registration in 60 seconds, over 500 extensions, and an AI mode that takes an idea, suggests names, and scores them. At the time of review, a dedicated.cloud promotional pagedisplayed a first-year price of 45,000 VND before VAT.
The purchase is cheap because the domain itself is only the first state change. Once registered, the name becomes the root of a company's public identity. DNS tells the internet where the website, mail servers, and other services are. The registrar account controls renewal, nameserver changes, registrant information, transfer locks, and authorisation codes. Email addresses built on the name become identifiers for banking, software subscriptions, and account recovery. A failed renewal can therefore interrupt far more than a website.
iNET sells into this growing dependency. The same showcase presents hosting, email, cloud servers, web tools, SSL, domain privacy, transfer assistance, pre-order, and a domain marketplace. Itsaffiliate programmerewards cross-product referrals, keeps attribution for 60 days, and advertises an additional 10% commission when customers renew services. Itsreseller programmegoes further: a reseller can sell domains, hosting, emails, and cloud services under its own brand, manage them via iNET's reseller interface, connect via an API, or use an iNET WHMCS module.
This business design is rational. Customer acquisition is expensive; a domain is annual and recurring; and each connected service increases the value of keeping the customer in a single control plane. This can also be useful for the customer. A single local support organisation can coordinate a domain move, DNS changes, website migration, and email configuration in Vietnamese. The customer avoids the blame-shifting that occurs when a registrar, DNS host, web host, email provider, and developer are all different companies.
The same convenience creates concentration. If a single account, support queue, or billing relationship governs the name, DNS, email, and hosting, a password compromise, disputed suspension, missed renewal, or poorly planned exit can affect them all together. iNET should therefore be evaluated less as a store selling several cheap products and more as a gatekeeper of operational identity. The domain is the cheapest click in the stack; it can become the most expensive component to lose.
Which iNET is the contracting party?
The legal anchor is unusually important because public records contain several similar iNET labels.
iNET's current footer identifiesCông ty TNHH Phần mềm iNET, tax code0103581701, with a registration dated 11 March 2009 in Hanoi and Trần Kiên as representative. The same footer appears onnhadangkytenmien.vn, a domain registration site linked to iNET's main ownership. VNNIC'sregistrar page for the companyindependently names Công ty TNHH Phần mềm iNET as an official ‘.vn’ national registrar and lists offices at 247 Cầu Giấy in Hanoi and 40 Hoàng Việt in Ho Chi Minh City.
ICANN's currentlist of accredited registrarsuses the English wording ‘iNET SOFTWARE COMPANY LIMITED’ and assigns IANA number 3234. This English label omits the ‘one member’ mention in the directory attribution, while the Vietnamese footer uses the legal form ‘Công ty TNHH’, or limited liability company. The reasonable identity treatment is to anchor the article and any contract on the Vietnamese legal name and tax code, then record the English variants used by ICANN and the directory rather than claiming the wording is perfectly uniform.
Historical material requires more caution. A 2012VNNIC announcementindicates that the recipient of a ‘.vn’ registrar certificate wasCông ty Cổ phần INET, a joint-stock company reportedly founded in 2005. This is not the same legal form as Công ty TNHH Phần mềm iNET. The current homepage also claims over 21 years of experience while its exact legal footer dates the software company to 2009. The available public evidence does not fully explain whether assets, contracts, accreditation, or brand history were transferred between the joint-stock company and the limited liability software company.
Network records reinforce the need for precision. VNNIC'sIP address member listseparately includes Công ty TNHH Phần mềm iNET underINETSOFT-VN, Công ty Cổ phần Giải pháp Công nghệ iNET underINETSOLUTION-VN, and Công ty Cổ phần iNET underINET-VN. Similar names are not proof of identical ownership, legal liability, or operational responsibility.
None of this invalidates the current identity. VNNIC now names the exact Vietnamese company as registrar, and the official site provides the exact tax code. This means a buyer should require that the purchase order, invoice, data processing terms, SLA, and domain registration contract all name the same party. If a reseller is involved, the customer should also know whether they are contracting with the reseller, with iNET, or with both for different parts of the service.
Registrar authority is real, but narrow
Accreditation answers one important question: is the provider recognised to perform registrar functions? It does not answer all questions about security, service quality, or financial resilience.
For ‘.vn’, VNNIC states that Công ty TNHH Phần mềm iNET is an official national registrar. VNNIC's currentmarket pageindicates there are ten national registrars and six foreign registrars for ‘.vn’, with over 690,000 active ‘.vn’ names and over 99,000 new registrations in 2026 at the time of access. iNET is therefore part of a regulated multi-registrar system rather than being the registry itself. VNNIC controls the national namespace and its registry rules; iNET is the customer-facing intermediary that takes instructions, validates information, collects fees, and submits transactions.
For generic top-level domains, ICANN accreditation places iNET in a different contractual system. Registries operate extensions such as.comor newer gTLDs; ICANN defines registrar obligations; and iNET provides the retail or reseller interface. The distinction matters whenever a support representative says an action depends ‘on the registry’ or ‘on ICANN’. Some restrictions are external policies. Others are choices in iNET's agreement or implementation.
An accredited registrar can prove access to registry systems and contractual status. Accreditation does not certify hosting availability, data centre design, incident response, quality of a domain suggestion, or security of a customer's password. Nor does it guarantee that every service sold alongside the domain is provided by the accredited entity. SSL depends on certification authorities. Hosting panels and security features depend on software vendors. Physical infrastructure may depend on data centre operators and carriers. Email deliverability depends on remote mail systems and reputation networks.
That is why the domain and cloud bundle should be broken down into authorities:
- VNNIC manages the national registry and recognises ‘.vn’ registrars.
- ICANN and the applicable registry govern gTLD registration and transfer.
- iNET controls the customer account, support workflow, and registrar actions it is authorised to perform.
- The customer controls the accuracy of registrant data, account credentials, legal name choice, and timely payment.
- Hosting, email, and cloud operations introduce separate responsibilities for infrastructure, software, and data processing.
The model is not a weakness; it is how the domain industry works. The risk appears when marketing compresses the chain into a single promise of security. A buyer needs to know which party can actually restore a deleted record, issue an authorisation code, undo a disputed change, recover a backup, diagnose a routing failure, or compensate for an outage.
From an idea to a production dependency
iNET's customer journey begins before the buyer has selected a name. Theregistration interfaceallows a user to describe an idea, generate candidates, check availability, see an AI score, place a name in the cart, and proceed to payment. It also refers to pre-order and secondary market services. This makes the top of the funnel feel like search and e-commerce rather than infrastructure procurement.
Registration then becomes an identity process. iNET's currentservice agreementstipulates that individuals registering ‘.vn’ names must perform eKYC with a Vietnamese ID card or passport, while organisations must provide a signed registration declaration with the organisation's digital signature. The agreement states that incomplete records are not activated. For international domains, iNET sends registrant verification messages from[email protected]and warns customers not to trust other addresses.
The customer pays in advance. Individual users can top up funds via the account, transfer money, or use supported payment gateways. Resellers maintain a deposit balance that is deducted as registrations and renewals occur. Once a registry accepts the order, domain fees are non-refundable, even if the buyer never uses the name. This is not just iNET's commercial preference: registration creates an external transaction with the registry that cannot be treated like returned physical stock.
The name is then attached to services. DNS points to the website and mail systems. iNET advertises domain privacy, DNSSEC, domain locking, email forwarding, and a landing page tool. Hosting customers can use OnePanel or cPanel; cloud customers receive server access; email customers create mailboxes; SSL customers manage certificate validation; and support interactions go through portal tickets, live chat, phone, or email.
At this point, the account has become an operational graph. A change to the registrant email can affect transfer approval. A nameserver change can affect the website and email. A domain expiration can make services appear to fail even if the underlying server is healthy. iNET's terms explicitly state that when a domain is suspended, expires, or is deleted, derived services such as the website, hosting, and email under that name also stop working. This is a factual description of dependency, not an upsell metaphor.
The support advantage is clear. iNET claims to offer free assistance for transferring services to its platform and 24/7 support. A small business without an internal administrator may prefer a local technician who can see the registrar, DNS, and hosting aspects of the problem. But the customer should maintain independent control: a business mailbox outside the domain for emergency contacts, more than one account administrator, documented registry data, exported DNS zones, offline backups, and a record of authorisation codes and renewal dates.
AI can suggest a name; it cannot eliminate risk
The AI feature is commercially smart because naming is the moment of maximum uncertainty. A user may know the business idea but not the available wording. iNET's interface invites a natural-language description, suggests names, and assigns scores. It turns an empty search box into guided discovery and can increase purchase conversion.
The public documents reviewed do not identify the model provider, scoring methodology, retention period for user prompts, use of submitted business ideas for training, or rate of legally problematic suggestions. The absence of these details does not mean the tool is dangerous. It means the AI feature should be treated as a convenience layer, not a due diligence system.
iNET's own agreement makes the legal limit explicit. The customer selects the domain and is responsible for avoiding infringement of trademarks, trade names, and other rights. iNET states it cannot verify all possible conflicts and may suspend, lock, withdraw, or transfer a name when required by a competent authority or dispute decision. An AI score therefore does not mean a name is legally clear, culturally appropriate, commercially sustainable, or safe from phishing resemblance.
Buyers should ask four simple questions. Is the user description stored? Is it sent to a third-party model outside Vietnam? Does the tool use customer inputs to improve a shared model? Can an organisation disable AI assistance and perform ordinary deterministic availability searches? These questions become more important when the submitted description contains an unreleased product name, acquisition plan, or regulated project.
The deeper problem is psychological. A generated name looks like a recommendation, and a score looks like proof. The registrar is best placed to resist this interpretation. The interface should keep availability, price, renewal price, registry policy, and legal liability visually distinct from the model's creative opinion. AI can help find the door; it should not imply the room behind has been inspected.
The control plane is assembled from many vendors
iNET's product catalogue describes a broad stack of local infrastructure, but its architecture is not a single proprietary system.
On shared hosting, iNET markets OnePanel and cPanel, CloudLinux isolation, antivirus, a web application firewall, Let's Encrypt certificates, JetBackup, LiteSpeed, and NVMe storage. Its currentCloud Hosting pagealso offers a seven-day trial and an MCP server that can allow AI tools to interact with hosting functions. Asoftware licensing pagesells or supports DirectAdmin, cPanel/WHM, CloudLinux, and LiteSpeed licences. These are familiar components in the hosting industry and can reduce the cost of providing a usable platform.
They also create a layered liability model. cPanel or OnePanel governs administrative actions. CloudLinux is intended to isolate shared hosting tenants and enforce resource limits. LiteSpeed handles web traffic. Antivirus and web application firewall rules attempt to detect malicious files or requests. JetBackup creates recoverable copies. Let's Encrypt or another CA participates in TLS issuance. A failure or vulnerability in any layer can affect service without being caused by the physical server.
Public descriptions of iNET's features include two-factor authentication, website isolation, real-time malware scanning, bot management, CMS threat warnings, ModSecurity logs, and WAF. These are useful controls, but a feature list does not establish deployment coverage or effectiveness. A buyer should ask whether two-factor authentication covers the SSO account, reseller account, registrar modifications, support-assisted resets, and hosting panels; whether staff can bypass it; how long logs are retained; who reviews WAF alerts; and whether isolation has been independently tested.
The cloud server side transfers more administration to the customer. iNET sells Cloud Server and Cloud VPS as virtual infrastructure, but its agreement states that the customer is responsible for the software licences, operating systems, applications, and configurations they install. The provider has no general obligation to configure or intervene in the customer's software, unless a separate contract or managed service package provides otherwise. Most importantly, the terms state that Cloud VPS and Cloud Server customers must perform their own backups and that iNET is not responsible for data stored on these services.
Email adds another chain. iNET advertises domain emails, dedicated email servers, SpamAssassin or MagicSpam, SSL, and migration support. A dedicated email page describes independent resources and IP addresses for certain plans. Yet deliverability depends on sender behaviour, DNS records, remote provider filters, and IP reputation. The SLA excludes outages where messages are classified as spam, a receiving system temporarily rejects the server IP, or a domain or link appears on a spam or phishing blacklist. The customer buys a mail platform, not a guarantee that every recipient will accept every message.
DNS Proxy is another separate service. iNET's agreement describes it as an intermediary intended to hide the origin server address and improve security against attacks, while expressly disclaiming absolute anonymity. The customer remains responsible for the origin's configuration and content. This is operationally important because a proxy can hide hosting topology, but a configuration error can expose the origin or cause an outage that falls outside the provider's liability.
The architecture is therefore best understood as orchestration. iNET combines registry connections, identity verification, payment, customer portals, control panels, virtual infrastructure, third-party software, email filtering, certificates, network transit, and support. Its value lies partly in making these pieces usable together. Its risk lies in the possibility that the customer sees a logo and assumes a single seamless guarantee.
What AS149068 proves—and what it does not
The supporting network label isINETSOFT-AS-VN, associated with AS149068. The public routing evidence makes it more than a marketing phrase.
At the time of review, theAS149068 view on bgp.toolsdescribed the autonomous system as ‘iNET software one member company limited’, reproduced a registration record from APNIC at 247 Cầu Giấy, and showed the system originating103.72.96.0/22and2001:df0:1b::/48. The view marked the routes as having valid RPKI coverage and showed AS135905 in its observed connectivity. VNNIC's member list independently records Công ty TNHH Phần mềm iNET asINETSOFT-VNsince 21 September 2016.
This evidence supports three limited conclusions. The exact company name is associated with Internet number resources. An autonomous system bearing that name was visible in public BGP data. The company has at least some ability to originate address space rather than appearing only as a retail storefront.
It does not prove that iNET owns a data centre. It does not identify the building in which a customer's virtual machine runs, the amount of compute or storage installed, the number of customers sharing a server, the diversity of fibre entries, the number of upstream carriers available in a failure, or the quality of support. A/22contains 1,024 IPv4 addresses, but the number of addresses is not a capacity metric: addresses can be used densely or sparsely, routed for different purposes, filtered, leased, or attached to services that are not part of the customer's package.
The IPv6 description also illustrates why registry strings require caution. The public view associates the/48description with ‘iNET Corporation Company’, while the autonomous system description uses the one-member software company label. This may reflect legacy naming, a related operator, or administrative inconsistency. It should not be converted into an unsupported claim about inter-entity ownership.
No public PeeringDB profile for AS149068 was identified in the public records reviewed. This is not evidence that the network lacks private peering, exchange connection, or additional upstream arrangement. PeeringDB is voluntary and can be incomplete. It means a buyer cannot deduce a rich interconnection footprint from a logo or an ASN alone.
The appropriate infrastructure inquiry is concrete: identify primary and secondary facilities; the legal operators of the data centres; power and cooling design; network carriers; diverse paths; DDoS arrangements; IPv4 and IPv6 routing; RPKI status; backup location; recovery objectives; and which service is affected if AS135905 or an international link fails. The public ASN is a starting point for that conversation, not the answer.
The acquisition price is not the cost of ownership
Domain pricing is designed to make the first decision easy. This is normal in a market where registries run promotions, extensions have different wholesale economics, and providers compete for customers who can then buy more services.
iNET's homepage at the time of review displayed a.cloudregistration offer of 45,000 VND and a higher comparison or renewal value. The dedicated.cloudpage showed a renewal at 760,000 VND per year, while the homepage display showed 740,000 VND. Both were exclusive of VAT. The discrepancy may be a timing, campaign, or cache issue rather than a contractual contradiction. It nevertheless demonstrates why a buyer should save the checkout quote and verify the renewal schedule instead of assuming the most prominent number is the long-term price.
The economics become clearer in iNET's channel design. Affiliates can earn up to 25% on a successful referral and an advertised 10% on renewals. The attribution cookie applies to all product pages, so a visitor referred for one service may generate a commission by buying another. Resellers are offered discounts up to 40%, deposit tiers, and white-label tools. These figures are business terms, not disclosed gross margins, but they show that commercial value lies in acquisition, cross-selling, and recurring service—not just the initial domain fee.
For the customer, the total cost has at least seven layers:
- The initial registration or transfer fees.
- The ordinary annual renewal and any post-expiration restoration fees.
- DNS security, privacy, or lock features not included in the base price.
- Hosting, email, SSL, website, backup, management, and support subscriptions.
- Migration work, including developer or administrator time.
- Downtime and business interruption during an incident or exit.
- The opportunity cost of reliance on a particular portal, panel, IP address, or support relationship.
The renewal value can be far higher than the invoice because the name accumulates recognition, links, search history, certificates, and email reputation. That is why ICANN'sExpired Registration Recovery Policyrequires gTLD registrars to make renewal, post-expiration, and redemption fees available, and encourages prominent disclosure when renewal is higher than registration. An acquisition price of 45,000 VND is not objectionable; not understanding the later price and recovery process is the risk.
Hosting pricing poses a parallel problem. ‘Unlimited’ bandwidth or storage is rarely literally unconstrained. iNET's agreement places such offers under a fair use policy, states that a database larger than 10 GB may exceed normal usage, and allows limiting, isolating, or suspending resources that threaten platform stability. A customer should size the workload against CPU, memory, process, inode, database, email, backup, and traffic limits rather than relying on the word ‘unlimited’.
Renewal is an operational control, not an accounting task
iNET'srenewal guidelinesstate that it normally sends reminders for ‘.vn’ 30, 15, 10, and five days before expiry and again on the expiry date. Its agreement states that a ‘.vn’ name can be held until the thirtieth day after expiry, then it is withdrawn. International names may enter a restoration state in which a customer pays both renewal and recovery fees.
The reminder sequence is useful, but email is not a control in itself. The registrant mailbox may be unattended, filtered, tied to an employee who has left the company, or hosted on the very domain that expires. A solid customer process should maintain a register of names, renewal prices, and responsible owners; use a separate emergency address; enable auto-renewal only with a monitored payment method; and reconcile renewal completion with registry data rather than relying on an invoice status.
The dependency can be circular. If the company's primary domain expires, the email address needed to receive a reset or transfer message may stop working. iNET's terms state that derived services under the name may stop when the domain stops. The correct architecture therefore includes an out-of-band recovery channel: a second domain, an external mailbox, a verified phone process, or documented executive escalation that does not depend on the affected name.
For gTLDs, ICANN requires pre-expiration notices and a redemption grace period after registry deletion for most gTLDs. For ‘.vn’, the national process applies instead. A customer with a mixed portfolio should not assume every extension has the same lifecycle. The renewal policy should record the registry, registrar, grace period, restoration fees, transfer restrictions, and owner for each critical name.
Exit rights exist, but timing and preparation determine their effectiveness
Domain portability is stronger than portability for most cloud services because registry policy establishes a transfer mechanism. It still requires correct timing, account access, and cooperation.
VNNIC's current‘.vn’ registrar transfer processstates that the existing registrar must not impede a transfer once the registrant has fulfilled its obligations. The losing registrar unlocks the name and provides an authorisation code; the customer provides it to the gaining registrar; and the transfer should be completed within five working days of the gaining registrar's submission. Transfers are restricted during the first 60 days after registration, the last 30 days before expiry, when the name is suspended, in dispute, or undergoing processing for a violation.
iNET's agreement reflects the 60- and 30-day windows. This creates a practical trap for a customer who waits until the renewal becomes contentious. A name in the last 30 days cannot simply be moved under the published ‘.vn’ process. The customer may need to renew first, stay with the current registrar for the restricted period, and transfer later.
For gTLDs, ICANN'sTransfer Policygives the registrant useful rights. Where no self-service facility exists, the registrar must provide the unique AuthInfo code and removeClientTransferProhibitedwithin five calendar days of the request. A registry generally completes a transfer unless the losing registrar rejects it within five days. The policy also allows 60-day locks after initial registration, a previous transfer, or certain registrant changes.
These rights protect the name, not the surrounding stack. Moving the registrar does not move the DNS zone unless the nameservers are changed. Moving DNS does not migrate a website. Moving a website does not preserve mailboxes, sending reputation, SSL private keys, backups, firewall rules, cron jobs, databases, reseller accounts, or support history. A customer who buys the full bundle should maintain an exit runbook for each layer.
The minimum runbook includes:
- a current list of names, registrants, contacts, locks, and expiration dates;
- exported DNS records and a known-good restore copy;
- source code, databases, uploaded files, and configuration outside the provider;
- mailbox exports, aliases, forwarding rules, and authentication records;
- documented ownership of certificates and secrets;
- an independent backup tested on another environment;
- a plan to reduce DNS TTL before the switchover;
- a parallel service during migration;
- a named person authorised to request unlocks and codes;
- a process for closing or retaining the old account after preserving legal records.
The best time to test this is not during a dispute. A buyer should perform a small transfer or export exercise while the relationship is healthy. Portability that exists only in policy but has never been exercised is an assumption.
The SLA is narrower than the heading
iNET'sSLAapplies to hosting, domain email, dedicated email, Cloud Server, and Cloud VPS. It commits to 99.9% monthly availability, calculated on a 30-day month as no more than 43 minutes of downtime. This is a clear numerical promise and a useful benchmark.
The remedy is service time rather than cash. If achieved availability is between 99% and less than 99.9%, the customer receives a 10% extension; from 98% to less than 99%, 50%; and less than 98%, 100%. The document states that maximum compensation is 12 months of service. The customer must submit a ticket from the account owner's email with the order code and reason, and iNET states it will process the request within three working days.
This remedy may be meaningful for a low-cost service, but it does not match the customer's loss. An hour of downtime on a cheap hosting plan can interrupt a much larger e-commerce or communications operation. Adding service days compensates the invoice, not the lost orders, staff time, or reputation damage.
The exclusions are extensive. Scheduled or emergency maintenance, force majeure, government requirements, international link failure, data centre failure, DDoS or targeted attack beyond reasonable defence, customer configuration, resource overuse, expired service, upgrades, third-party software, and customer connectivity can all be excluded from compensation. Hosting-specific exclusions include malicious code in the website, traffic-generating programs, IP blocking used for attack prevention, and application code errors. Email exclusions include client software, spam classification, and blacklisting.
Cloud exclusions include administrator actions, malware in the operating system, and internal network configuration.
Several exclusions are commercially understandable. A provider should not guarantee a customer's broken code or unlicensed software. The problem is cumulative scope. If the physical data centre, international carrier, DDoS attack, operating system, application, and customer configuration are all excluded, the compensated outage remaining may be limited to a narrower failure in iNET-controlled infrastructure that the customer can prove and measure.
Buyers should therefore define the measurement before signing:
- Which monitoring source determines unavailability: iNET's telemetry, the customer's probe, or both?
- Is severe performance degradation considered unavailability?
- Is DNS failure included if the server remains reachable by IP?
- Is an account suspension later found erroneous counted as unavailability?
- Does scheduled maintenance have a maximum duration and notice period?
- Are data centre and transit failures really outside all service liability even when iNET selected those providers?
- Does the provider own incident coordination when a third party causes the outage?
- Can a business negotiate service credits tied to monthly fees, incident reports, and termination rights for chronic failure?
The published SLA is a retail baseline. A business placing a critical workload on the platform should treat it as the start of negotiation, not the complete resilience design.
Refunds protect the trial, not the domain
iNET'srefund policy, updated 1 January 2026, covers hosting, domain email, dedicated email, Cloud Server, and Cloud VPS. It allows a 100% refund during the first 30 days only when the service suffers a technical problem or does not meet a promised technical specification. From day 31, the SLA remedy applies instead.
The policy excludes domains and SSL because they are registered immediately with VNNIC, ICANN-related registries, or certificate providers. It also excludes bundled free time, points, and services cancelled for policy violation. Refunds are requested via a ticket and are paid to the original account or iNET wallet within three working days of processing.
This is not a general satisfaction guarantee. A customer cannot assume that a poor fit, difficult administration, application incompatibility, or change of mind produces a refund. The trial period should therefore be structured around measurable requirements: application versions, database support, mail delivery, backup restoration, control panel access, response time, and migration support. If a specification matters, it should be recorded before purchase so that ‘not as promised’ can be demonstrated.
The domain exception is particularly important because the AI interface encourages exploration. Once the user confirms and the registry completes the transaction, a misspelling or inappropriate choice is not returnable. The customer must register another name and absorb the first fee. The cheap front end should not encourage casual confirmation of a legally and operationally durable identifier.
The backup policy makes the customer the last line of defence
Backups often appear as a feature icon, but iNET's agreement provides more useful details than the marketing page.
For hosting, the company states that data is backed up once per week and one copy of the most recent week is retained. For email, it states that data is backed up once every two weeks with one copy retained. For Cloud VPS and Cloud Server, the customer must create its own backups and iNET disclaims all responsibility for data stored on those services.
One retained copy is not a recovery strategy for every failure. If corruption, malware, or unnoticed deletion persists within the backup window, the latest copy may reproduce the problem. A weekly hosting copy can mean nearly a week of data loss. A two-week email interval can be inadequate for an active mailbox. The terms do not disclose, in the material reviewed, whether the copy is immutable, encrypted, stored at another site, tested for restoration, or included in the base service.
Expiration creates another countdown. The agreement states that hosting and email data may be deleted three, seven, 15, or 30 days after expiry depending on how long the customer has used the service. Cloud data may be deleted after three days for a trial, seven days for a service used less than six months, or 15 days for longer use. These windows turn a billing problem into a data recovery event.
A production customer should maintain at least one backup under different credentials and ideally with a different provider or physical failure domain. It should test restoration in a clean environment, record recovery time, and verify that DNS, certificates, mail records, and application secrets are included. ‘The backup exists’ is not the same as ‘the business can restart’.
Local support is part of the product
For many small and medium Vietnamese organisations, support is not an accessory. It substitutes for an internal system administrator.
iNET markets 24/7 support, free migration, and long experience. VNNIC lists physical registration offices in Hanoi and Ho Chi Minh City. The domain workflow is available online, and a VNNIC account of iNET'sonline ‘.vn’ registration systemindicates the company has moved individual and organisational procedures online under VNNIC's direction.
iNET'scomplaints procedurestates that ordinary quality complaints should be resolved within five working days, complex cases taking no more than 20 days. This is a published complaints timeframe, not a technical incident response time. A critical website cannot wait five days for initial support. Buyers need separate severity definitions, acknowledgement targets, escalation contacts, and restoration objectives.
The current service agreement also limits support scope. iNET supports configuration or installation as part of the published service or purchased package, but it has no obligation to configure the customer's applications, operating systems, code, or databases, unless the parties separately agree or the customer purchases an appropriate managed service. This distinction should be explicit at the point of sale. ‘We support Cloud Server’ may mean the virtual machine and network are available, not that iNET will fix the customer's application at 2 a.m.
Support quality is difficult to verify from public evidence. The homepage contains customer testimonials and a claim of over 50,000 customers, but the sources reviewed did not provide independently audited customer numbers, ticket statistics, first-response distributions, or satisfaction methodology. A procurement team should request anonymised service metrics and speak to reference customers with a similar workload rather than relying on a few selected comments.
Security features do not remove account risk
Registrar and hosting security starts with the account because control panel authority can be more damaging than server access alone.
iNET advertises two-factor authentication in OnePanel, website isolation, antivirus, WAF controls, and security logs. Its terms protect certain registrant fields from public WHOIS display by default and warn customers to use the official registrant verification address. Its privacy policy states it will notify authorities and affected members if a server attack leads to personal data loss. Its dedicatedpersonal data policydescribes customer rights and states that information may be shared or jointly processed with VNNIC and international domain management organisations for registration and maintenance.
The same documents place substantial responsibility on the customer. Users must protect usernames and passwords, maintain accuracy of registration data, manage software licences, and secure customer-controlled systems. The SLA excludes malware in customer websites or cloud operating systems and many failures caused by configuration or third-party software.
This allocation is typical for infrastructure services, but the registrar account deserves stronger protection than an ordinary retail login. An attacker who changes the nameservers can redirect web traffic and email. An attacker who changes the registrant contact can complicate recovery. A support-assisted reset can bypass technical controls if staff rely on weak identity evidence. A compromised reseller account can affect downstream customers who may not know iNET is the underlying provider.
Buyers should demand:
- phishing-resistant MFA for every privileged account;
- separate named administrators rather than shared credentials;
- role-based access that isolates billing, DNS, hosting, and transfer authority;
- approval or a delay for nameserver, registrant, and transfer changes;
- immutable audit logs with export;
- an out-of-band alert channel;
- documented evidence of support-assisted reset and fraud escalation;
- proper domain locking at the registry;
- DNSSEC with clear key ownership and renewal procedure;
- annual recovery exercises.
iNET's public pages mention DNSSEC and domain locking, but the documents reviewed do not establish which extensions support which lock, whether ‘domain locking’ means client-level transfer lock or registry-level lock, how changes are approved, or whether high-assurance controls cost extra. These details should be obtained in writing for critical names.
A disclosed hosting incident is evidence, not a complete history
iNET published a notice titled‘Information on certain websites hosted at iNET having illegal links inserted’. In the accessible text, the company states it acted after reports from customers and the community and observed unusual access from international IP addresses to customers' cPanel accounts.
This is useful evidence because it shows a real class of event: unauthorised access to hosting administration followed by website modification. It also demonstrates that community reports can initiate a platform review. The available notice does not establish how many sites were affected, whether credentials were stolen via client devices or provider systems, whether a cPanel vulnerability was involved, how long the access persisted, what logs were retained, or whether independent investigators validated the conclusion.
It would be incorrect to label the event a confirmed breach of iNET's core platform based on the available evidence. It would be equally incorrect to infer that no significant incident has occurred because a complete public archive was not found. The appropriate procurement response is to request the post-incident report, root-cause classification, improvements to affected controls, and the notification standard.
The incident also exposes the weakness of a simple shared-responsibility slogan. If the customer's credentials were compromised, the customer may be the initial source of risk. The provider still controls anomaly detection, connection telemetry, rate limits, IP alerts, panel hardening, and recovery tools. A mature service measures both sides: how fast abnormal access is detected, how fast affected accounts are isolated, whether clean backups exist, and whether the same technique can recur.
No public provider-wide status history with independently measurable availability was identified in the frozen pack. Buyers should ask whether iNET operates a status page with historical incidents, component-level impact, start and end times, root-cause reports, and subscription alerts. Without that history, the 99.9% promise cannot be benchmarked against a long-term public record.
Abuse control can protect the network and interrupt the customer
Hosting and registrar companies must act against phishing, malware, spam, copyright abuse, and illicit content. Slow action can harm victims, blacklist shared infrastructure, and attract regulatory intervention. Fast action based on weak evidence can disable a legitimate business.
iNET publishes anabuse reporting channelwith dedicated email addresses, a phone number, and a ticket process. The page states that complaint volume is high and the company may only respond when more information or clarification is needed. The service agreement allows immediate action when iNET detects a violation or receives a valid complaint from authorities, technical partners, the community, third parties, browsers, security software, or anti-spam organisations.
These measures can include traffic limitation, resource isolation, hosting suspension, email restriction, domain locking, or service termination without notice in severe cases. Some violations result in no refund. The agreement also states that an account may be automatically locked before notice when resource usage threatens the system.
The operational logic is defensible: a shared host cannot leave a phishing page active while conducting a leisurely contractual debate. The due process risk is also real. Browser warnings, community reports, and automated reputation systems can be wrong. A competitor can submit a complaint. A compromised website can make an otherwise legitimate customer appear malicious.
A professional customer should therefore request an abuse matrix:
- what evidence triggers an investigation, temporary isolation, or termination;
- whether the response can target a URL, mailbox, or virtual host rather than the entire account;
- how the customer is notified when the notice is safe;
- what evidence is provided;
- how fast an appeal is reviewed;
- how data can be exported during suspension;
- whether an erroneous action counts in the SLA;
- when law enforcement or a registry controls the decision;
- how resellers pass notices to the actual end user.
The quality of an abuse service is measured not only by how quickly it removes content. It is measured by its ability to act proportionally, preserve evidence, restore legitimate service, and explain which authority made the decision.
Data location is a contractual map, not a flag on a website
iNET's Vietnamese identity, local offices, and national registrar role can be valuable for customers who prefer support in Vietnamese, local billing, and a domestic counterparty. None of these facts alone establishes where a workload, backup, log, support session, or AI request is processed.
Public network evidence identifies address resources and routing. It does not identify facilities. The SLA itself lists external data centre failure as a possible exclusion, implying that facility dependency must be understood separately from iNET's customer-facing role. The product pages reviewed describe hardware and software features but do not provide a complete map of primary, secondary, and backup locations or of every subcontractor.
Vietnamese data rules make this map more important. The 2025Personal Data Protection Lawentered into force on 1 January 2026. Itsimplementing decree 356/2025/NĐ-CPstipulates that cloud contracts involving personal data should identify data flows, party roles, security measures, involved personnel, and changes that could affect the data. It also addresses subcontractors and defines cross-border transfers as including moving data collected in Vietnam to foreign servers or cloud services outside Vietnam.
Local hosting can simplify some data flow questions, reduce international latency, and provide a national support path. It does not automatically satisfy the law. A locally marketed service may use foreign control software, certificate services, anti-spam filtering, AI models, support tools, or backups. Conversely, a foreign service is not automatically prohibited; the applicable obligations depend on the data, roles, transfer path, and legal basis.
iNET's own personal data policy states that registration information may be shared with VNNIC and international domain management organisations. This is necessary to provide the domain service, but it demonstrates why ‘all data stays in Vietnam’ would be too broad an assumption. Registrant data, billing data, website content, cloud workloads, support tickets, and AI search prompts may follow different paths.
A procurement data map should answer:
- Where are production, replica, and backup data physically stored?
- Which legal entity operates each facility?
- Which third-party panels, monitoring systems, anti-spam filters, CAs, and AI services receive data?
- Can support staff access content, and from where?
- Are logs or backups transferred outside Vietnam?
- What is the role of the customer and iNET under the personal data law?
- What evidence of deletion, export, and audit is available on termination?
- How are subcontractors changed and notified?
- Which encryption keys are controlled by the customer?
- What incident notification timeframe applies?
Data sovereignty is not achieved by choosing a local logo. It is achieved by making the actual processing chain visible and contractually governable.
The reseller layer can hide the real dependency
iNET's reseller programme is more than a sales channel. It allows another company to bundle iNET's services under its own brand, set retail prices, use a provided management system, connect via WHMCS, or build against an API. The application asks resellers their expected monthly volume, deposit budget, and preferred administration model.
This expands distribution and can give customers support from a trusted local agency. It also creates a three-party control problem. The end customer may believe the agency is the registrar or host while iNET performs the underlying registry and infrastructure work. The agency may control client registration, renewal reminders, and support communication. iNET may have technical authority but no direct relationship with the end user's staff.
ICANN's expired registration policy specifically requires that renewal and restoration fees be visible on reseller websites as well as registrar websites. This rule exists because the customer should not lose transparency simply because a reseller sits in front of the accredited registrar.
Before buying through a reseller, the end customer should establish:
- whose name appears as the domain registrant;
- whether the customer receives direct access to the registrar account;
- who can obtain the authorisation code;
- who receives expiry and abuse notices;
- whether iNET will support the customer directly if the reseller disappears;
- who owns the hosting data and backups;
- whether the reseller can move services without consent;
- which party invoices, refunds, and bears liability;
- how an iNET service credit reaches the end customer;
- what happens to the reseller's deposit and downstream names in case of insolvency.
A white-label interface should not become white-label ownership. The customer should remain the registered registrant of its domain and should be able to prove that status independently.
Competition comes from unbundling as much as from rival bundles
iNET competes in a substantial ecosystem of Vietnamese registrars and hosting providers. VNNIC's current list includes P.A Việt Nam, Mắt Bão, GMO-Z.com RUNSYSTEM, Nhân Hòa, ESC, VinaHost, Tino, BKNS, and Long Vân alongside iNET. VNNIC's2022 Vietnam Internet Resources Reportplaced iNET at 10.49% historical ‘.vn’ domains maintained, behind P.A Việt Nam, Mắt Bão, GMO, and Nhân Hòa at that time. This figure is not current market share and should not be treated as such. More recently, VNNIC named Công ty TNHH Phần mềm iNET as theregistrar with the best ‘.vn’ name growth in 2023.
The obvious comparison is another local bundle: domain, hosting, email, cloud, and Vietnamese support from one provider. The less obvious substitute is deliberate separation.
A company can keep the registrar with one provider, authoritative DNS with another, email with a specialised SaaS service, and compute with a cloud or host chosen for the workload. This increases vendor management work but reduces the chance that one account failure disables all layers. A company can also use iNET only for ‘.vn’ registration while hosting elsewhere, or host at iNET while keeping the domain with an independent registrar.
Global registrars and clouds can offer broader automation, security tools, or international footprints. Local providers can offer better language, payment, regulatory familiarity, and convenient migration. Hyperscalers can provide richer infrastructure primitives but leave the customer responsible for architecture and cost control. Managed WordPress or e-commerce platforms can replace much of the hosting stack but increase application-level lock-in.
The choice should follow the failure mode. If local support and a single responsible helpdesk are the priority, an integrated provider may be superior. If domain custody is existential, separating registrar and production host may be prudent. If the workload requires multi-region recovery or specialised compliance, the public retail bundle may require an enterprise contract or a different platform. No category is universally safer; the architecture should make the chosen dependency explicit.
The procurement test is a controlled failure
A polished sales demo proves a service can work under prepared conditions. A controlled failure shows whether it can be trustworthy.
For a domain and cloud provider, the most revealing pilot is not launching a brochure website. It is the deliberate exercise of the operations that become difficult under stress:
- Verify the legal chain.Match the contract, invoice, registrar registration, privacy terms, and SLA to Công ty TNHH Phần mềm iNET and tax code 0103581701. If a reseller is involved, document each party and responsibility.
- Create resilient account ownership.Use named administrators, strong MFA, an external emergency address, and a documented reset process. Confirm whether registrar, SSO, reseller, OnePanel, and cPanel privileges are controlled separately.
- Register a non-critical test domain.Perform eKYC or organisational signing, inspect the recorded registrant data, enable available locks and DNSSEC, and verify the customer—not an agency employee—appears as registrant.
- Perform a transfer exercise.After any required lock period, request unlocking and authorisation information. Measure response, proof requirements, and communication. Do this with a test name, not the company's primary identity.
- Simulate a renewal failure.Confirm who receives reminders, what happens at expiry, when DNS is interrupted, what recovery costs apply, and whether the emergency contact still works when the domain is not.
- Map the hosting architecture.Obtain the facility, data centre operator, network providers, virtualisation layer, storage design, backup location, and recovery dependency. Ask which facts are held by iNET, provided by the vendor, or simply product page claims.
- Test backup restoration.Delete a test site or corrupt a test database, then recover it. Record available restore points, time, support action, and data loss. For Cloud Server, restore from a customer-controlled copy in a separate environment.
- Measure the SLA boundary.Run external HTTP, DNS, email, and network probes. Agree how partial degradation, packet loss, control panel failure, and erroneous suspension are counted. Archive maintenance notices and incident timestamps.
- Exercise support escalation.Open a severity one test under agreed conditions. Determine whether 24/7 means acknowledgement, staff diagnosis, or only ticket capture. Identify who owns coordination between the data centre, carrier, and software provider.
- Review the abuse process.Submit a benign test notice or do a tabletop exercise on a compromised site. Confirm containment scope, appeal, evidence preservation, customer notification, and restoration.
- Inspect security controls.Request the current penetration test scope, vulnerability management process, privileged access design, logging, staff reset controls, incident history, and any certification. A certificate should be linked to the exact entity, location, service, and validity period.
- Build the data flow register.Map separately registrant data, billing, website content, logs, backups, support tickets, and AI prompts. Record subcontractors and cross-border paths under the 2026 personal data framework.
- Calculate the three-year cost.Include renewal, VAT, normal package price after promotion, backup, management, licences, additional IPs, restoration, migration labour, and exit overlap. Do not annualise the acquisition discount.
- Rehearse the exit.Export DNS, data, emails, and configuration; reduce TTL; start a parallel service; switch over; validate; and confirm the old environment can be closed without losing legal or technical records.
The provider that performs well on these tests has evidence of operational trust. The provider that answers only with feature lists asks the customer to fund the missing proof.
The evidence gaps that matter
The public record reviewed is rich enough to establish identity, registrar status, product scope, published terms, and a supporting network footprint. It is not rich enough to answer all diligence questions.
First, standalone financial resilience is unknown. No audited accounts, revenue, cash position, customer concentration, or insurance evidence for Công ty TNHH Phần mềm iNET was identified. The claim of over 50,000 customers on the homepage is self-reported and is not accompanied by a definition of active customer or an independent audit.
Second, the historical entity chain is incomplete. The current exact company is verified, but the relationship between the 2005 joint-stock company mentioned by VNNIC, the 2009 limited liability software company, the other network members labelled iNET, and the homepage's claim of over 21 years requires documentary explanation.
Third, infrastructure location and redundancy remain under-disclosed. The ASN and prefixes are real evidence, but no complete public facility map, capacity statement, carrier diversity diagram, PeeringDB profile, disaster recovery topology, or backup location schedule was identified.
Fourth, security assurance is heavy on features and light on evidence. Public pages describe two-factor authentication, isolation, antivirus, and WAF functions, but the sources reviewed did not establish an independently validated control baseline for the full registrar, hosting, and cloud environment. No comprehensive public vulnerability or incident archive was found.
Fifth, the AI layer is opaque. The public interface shows suggestion and scoring, but not the model, provider, data retention, evaluation method, or legal risk controls. This matters most for confidential naming exercises and for buyers assuming a score carries professional judgement.
Sixth, support performance is not independently measured. The published complaints timeframes and 24/7 availability claims are useful commitments, but no public distribution of first-response, restoration, escalation, or repeat incident rates was identified.
Seventh, price displays are dynamic. Promotions, renewal values, reseller discounts, and bundled giveaways can change. A saved quote and signed schedule are stronger evidence than a product page viewed months later.
Finally, the absence of a public incident, outage, or complaint should never be interpreted as proof that none has occurred. The appropriate monitoring points are changes in the legal footer, registrar status, published terms, liability cap, SLA exclusions, data centre disclosures, BGP origins, RPKI state, support channels, security notices, and renewal pricing.
Owning the door means being able to leave
iNET's proposition has real utility. It gives Vietnamese customers a locally recognised registrar, online registration, a broad service catalogue, integrated administration, migration assistance, reseller tools, and public rules for refunds, availability, abuse, and complaints. VNNIC and ICANN records support the registrar role, and public routing data supports a real network presence.
The strongest criticism is not that iNET bundles services. Bundling can reduce complexity and make local support economically viable. The risk is treating convenience as proof that every layer carries the same authority, resilience, and recourse.
The domain name is a low-cost purchase with unusually high downstream power. Once it anchors DNS, email, hosting, and account recovery, the customer is no longer buying a string for a year. It is entrusting a provider with the door through which the organisation is found and authenticated.
This trust is justified only when the customer can verify the legal gatekeeper, renew without surprise, recover without the affected domain, restore from an independent backup, understand where data travels, measure an outage, contest a suspension, and move each layer elsewhere. The decisive buying question is therefore not ‘How quickly can iNET register the name?’ It is ‘Once the name becomes indispensable, can we still prove we own the door?’

