Summary
- VIET HOSTING COMPANY LIMITED can be anchored to Vietnamese company identifier 0313752826, a 2018 VNNIC registrar list, and APNIC records for AS140781 and
103.161.212.0/23. The address, named contact, telephone number andviethosting.comemail in those records form a strong identity chain. - VietHosting's current website names a different contracting company, VietHosting Solutions Company Limited, with tax identifier 0318129340. It shares the older company's mailing address, brand, main telephone number and support domain, but the reviewed public material does not explain the legal transition or say which older obligations and number resources the current company controls.
- AS140781 was visibly originating one RPKI-valid IPv4
/23on July 15, 2026. RIPEstat saw it through all 326 IPv4 observation peers and through no IPv6 peers; IPinfo classified it as single-homed and named ODS Joint Stock Company as its one upstream. That is meaningful network proof, but it is not evidence of diverse transit, a particular server fleet, customer count or service outcome. - The commercial site publishes unusually useful detail on bandwidth, backups, support and compensation, yet its service documents need reconciliation. The main SLA promises at least 99.5% uptime while the same page's FAQ and the company introduction say 99.9%; support wording also ranges from a typical 15-30 minute reply to a maximum four-hour initial response. Buyers should make the signed order and attached service schedule controlling.
A name that opens two files
Hosting is sold through compression. A short name is made to carry a long chain of implied assurances: that there is a company to invoice, a network to reach, a server to recover, a technician to call, a backup to restore and a contract that decides who bears the loss. The chain is easy to overlook when a website loads quickly and the order form offers familiar products. It becomes much harder to overlook during an outage, an abuse complaint, a billing dispute or a migration.
The public case around VIET HOSTING COMPANY LIMITED is useful because it is neither empty nor perfectly neat. The BTW directory supplies a company identity under that exact English name. A Vietnamese company-record index supplies a tax identifier, formation date, representative and address. VNNIC, the national internet resource authority, historically connected the Vietnamese legal name to viethosting.com. APNIC then connected that same legal name and address to an autonomous system and an IPv4 block. Current routing observation shows the block in use. Those are separate forms of evidence, and together they establish considerably more than a marketing phrase.
The current VietHosting website complicates the picture in a way that matters. It does not identify VIET HOSTING COMPANY LIMITED as the present provider. Its company page says the current business is Cong ty TNHH Giai phap Viet Hosting, translated there as VietHosting Solutions Company Limited, and gives a different tax identifier. Its service-level document names that newer company as the provider. At the same time, the site preserves the older company's mailing address, main telephone number, support email and brand. The result looks like continuity, but the legal mechanism of that continuity is not stated in the material reviewed.
That distinction should not be inflated into an allegation. Businesses change entities, transfer brands, reorganise contracts and retain operational assets for ordinary reasons. A later company can take over a website, a support team and customer relationships from an earlier one. An older company can remain the registrant of number resources while a related operator uses them under an agreement. Public records can also lag a perfectly valid transfer. The problem is not that two names exist. It is that a customer cannot derive the allocation of responsibility from the shared brand alone.
There are therefore two questions, not one. The first is whether the VIET HOSTING COMPANY LIMITED name is backed by identifiable company and network records. It is. The second is whether those records prove the precise operating assurance offered today at VietHosting. They do not do that without a bridge to the current contracting company, the selected product and the contractual service boundary.
The older legal identity is unusually traceable
The older company's public anchor is tax identifier 0313752826. A Vietnamese legal-information index presents the domestic name as Cong ty TNHH Viet Hosting, the international name as VIET HOSTING COMPANY LIMITED and the abbreviation as VIET HOSTING CO., LTD. It gives April 12, 2016 as the issue date, Nguyen Thanh Tam as the legal representative and 232/7 Ngo Quyen in Ho Chi Minh City as the address. Its principal registered activity is information-technology and other computer-related services, with programming, computer consultancy and systems administration among the additional activities shown.
This is a useful lead, but it is not a fresh certified company extract. The index says the company information was last updated about two years before the article date and warns that the material is for reference. Administrative geography in Ho Chi Minh City has also changed: the index presents an updated ward name, while older records use Ward 8, District 10. The street number remains the important matching element. A procurement team should still obtain a current enterprise-registration certificate and tax-status confirmation before relying on the record for a contract.
An official historical source adds weight. VNNIC's 2018 report on internet resources in Vietnam listed Cong ty TNHH Viet Hosting and www.viethosting.com among international domain-name registrars operating in the country. That does not prove current accreditation, current scale or the quality of any hosting service. It does show that the legal name and domain were publicly connected in an official industry document by 2018. The relationship was not invented by a recent directory or an internet-number database.
The APNIC records carry the chain forward. AS140781, registered on January 14, 2021, is named VIETHOSTINGCO-AS-VN. Its description names VIET HOSTING COMPANY LIMITED and the same 232/7 Ngo Quyen address. The administrative and technical contact is Nguyen Thanh Tam, with the telephone number that corresponds to 0966 70 70 70 and the email [email protected]. The IPv4 block 103.161.212.0/23, registered the same day, repeats the company name, address and contact details.
This combination is stronger than a loose name match. Legal representative, street address, telephone number and email domain all align. It is reasonable to say that VIET HOSTING COMPANY LIMITED was the named organisation behind those APNIC resources in 2021. It is also reasonable to connect the older company record, the VNNIC listing and the APNIC registrations to the VietHosting brand.
What the chain does not show is the later legal handover. APNIC still displayed the older company description at the time of review. The current site displayed the newer company. No public document in the reviewed material said that the autonomous system and address block were transferred, leased, operated under contract or retained by a related entity. That missing sentence is the central identity issue for a present-day buyer.
The current website names a different provider
VietHosting's company page is specific about the present identity. It names Cong ty TNHH Giai phap Viet Hosting, provides the English form VietHosting Solutions Company Limited, and gives tax identifier 0318129340. It lists a registered office at the ACM Building, 96 Cao Thang, Ho Chi Minh City, and identifies 232/7 Ngo Quyen as the working and mailing address. The support number 0966 70 70 70 continues, joined by a second number. The same viethosting.com email domain remains in use.
The website also supplies a brand chronology. It says earlier information-technology activity began under the IT-4VN.COM name in 2005, that a predecessor company was formed in 2009, and that VietHosting adopted its current domain and unified brand in 2016. These dates are company claims, not independently audited corporate history. The VNNIC report supports the 2018 connection between the earlier legal company and the domain, while the 2016 issue date in the company index is consistent with the older VIET HOSTING COMPANY LIMITED identity. The evidence does not independently establish every step back to 2005 or 2009.
More importantly, a brand history is not a legal succession schedule. The current site does not say whether VietHosting Solutions Company Limited acquired the older company, received specified assets, became a reseller, took an operating licence, or simply adopted the brand and contact infrastructure. It does not state whether contracts signed by VIET HOSTING COMPANY LIMITED were novated to the newer company. It does not identify who owns customer receivables, who controls AS140781, or which entity is responsible for historic data and support obligations.
The service-level agreement removes any doubt about the name a new customer is being asked to recognise. It explicitly defines the service provider as Cong ty TNHH Giai phap Viet Hosting. The homepage's payment section likewise says bank transfers go to that company. A buyer ordering today should therefore expect the invoice, bank beneficiary, terms, service schedule and data-processing commitments to use the newer legal name and tax identifier. If any document instead uses VIET HOSTING COMPANY LIMITED, that discrepancy needs an explanation before payment.
The shared address and phone create a credible continuity signal, not a substitute for the explanation. In practical due diligence, the provider can resolve this cheaply. It can supply the current registration extract; state the relationship between the two companies; identify the legal controller or authorised operator of the APNIC resources; and confirm whether any customer obligations moved from one entity to the other. A short, signed identity schedule would do more for assurance than another page of general reliability claims.
This issue matters even for a modest hosting order. The legal provider determines who can be pursued for a refund, who responds to a data request, who receives an abuse notice and who authorises an emergency route or server action. When those functions sit across related entities, the contract needs to say so. The public name can remain VietHosting; the accountability chain cannot remain implicit.
AS140781 is real operating evidence, within a narrow boundary
The network record is the strongest independent sign that the older company name was attached to an operating internet service. APNIC marks AS140781 active. It also marks 103.161.212.0/23 active and describes the block as allocated portable IPv4 space. A /23 contains 512 addresses. Registration is not the same as route operation, but current BGP observation closes part of that gap.
RIPEstat's snapshot for July 15, 2026 showed AS140781 originating exactly one IPv4 prefix, 103.161.212.0/23. All 326 of its IPv4 full-feed observation peers saw the autonomous system. The latest route observation was on the day of review, and the first qualifying observation for the ASN was in March 2021, shortly after the APNIC registration. The data counted one observed neighbour. This is a compact but broadly visible routing footprint, not an inactive identifier.
The route also had a valid Route Origin Authorisation. RIPEstat's RPKI validation found a valid ROA permitting AS140781 to originate 103.161.212.0/23, with more-specific announcements allowed down to /24. RPKI validity is an important routing control: networks that perform origin validation can distinguish this authorised announcement from one with an invalid origin. It reduces one category of routing error and hijack risk.
It does not certify the company, encrypt traffic, prevent every route leak, guarantee availability or prove that every address is used for a VietHosting customer. RPKI says the origin is authorised under the published ROA. It does not say whether the server behind an address is patched, whether a customer can restore it, or whether the contract covers a failure. The control is valuable precisely when it is kept in its proper technical frame.
The observed footprint is IPv4-only. RIPEstat saw AS140781 through none of its 322 IPv6 observation peers and counted no announced IPv6 prefixes. The APNIC evidence reviewed for the company also centred on the one IPv4 /23. This does not prove that VietHosting offers no IPv6 through any product or upstream arrangement. It does mean that AS140781 itself did not supply visible IPv6 origin evidence at the snapshot time. A customer requiring native dual-stack service should ask for the assigned IPv6 prefix, routing arrangement and test endpoint rather than infer support from the general hosting label.
IPinfo offered a compatible, more interpretive picture. It classified AS140781 as a stub or single-homed autonomous system, named ODS Joint Stock Company as the one observed upstream and showed no downstream networks. It associated the full 512-address block with the company and counted 36 domain names hosted across 36 addresses in its scan. Two addresses answered its recent ICMP probes from Ho Chi Minh City. Those observations are evidence of reachable services, but none should be turned into a customer total or uptime score.
Hosted-domain discovery is incomplete by design, and two successful pings say almost nothing about month-long service quality.
No network entry for AS140781 was returned by PeeringDB's API at the time of review. That absence is not evidence that the network lacks private interconnection, multiple physical circuits or a sophisticated internal design. PeeringDB participation is voluntary. It does mean the public evidence set does not provide an operator-maintained peering policy, facility list or exchange-port inventory to supplement the route view.
The defensible conclusion is therefore exact. VIET HOSTING COMPANY LIMITED has an active APNIC identity and a currently visible, RPKI-valid IPv4 announcement. The public route surface is small and appears concentrated behind one observed upstream relationship. It establishes network operation. It does not establish network diversity, datacentre resilience, contractual capacity or the current legal company's authority over the resources.
Single-homed is a design question, not a verdict
A single-homed classification deserves attention because hosting availability depends on more than whether the origin ASN is visible. If one upstream relationship is the only path from the origin network to the wider internet, an upstream outage, commercial dispute, route-filter error or congested handoff can affect the whole announced block. A small origin can still be well operated, and its upstream can have a resilient backbone. The concentration is nevertheless different from a design with independently contracted upstreams and diverse physical entrances.
The public record cannot reveal the entire topology. An operator may buy redundant links from the same upstream at different locations. It may use another provider through a service that remains hidden from simple adjacency summaries. Its datacentre may have diverse carriers while the portable /23 is announced under one primary routing arrangement. Conversely, two logical BGP sessions can share one conduit and provide less resilience than their count suggests. A buyer should not convert a third-party label into a final architecture judgment.
It should convert the label into questions. Which ASN will originate the customer's assigned address? Which provider or providers carry that route? Are the physical paths diverse from the rack to the building exits? What happens to the route when the primary session fails? Is there automatic failover, a tested manual procedure or no alternate path? Does a dedicated-bandwidth option alter the path or only the rate policy? How are route changes reviewed, and who can authorise an emergency withdrawal?
The one observed prefix also makes resource accounting important. VietHosting's dedicated-server page advertises options for substantial additional IPv4 allocations, including configurations reaching 256 addresses. Its VPS page advertises smaller address additions. A single /23 contains 512 addresses, so a few large assignments could consume a meaningful share if they came only from that block. The website may source additional addresses through other providers, route customer-owned space or apply eligibility conditions not visible on the page. The product options should not be read as proof that every quantity is immediately available from AS140781.
For an enterprise customer, the service order should state whether addresses are provider-assigned or customer-portable, the allocation size, justification requirements, route origin, reverse-DNS process and consequences at termination. The answer matters for migration. A workload tightly coupled to provider addresses can be more expensive to move than the monthly server price suggests. Network-resource evidence is most useful when it reveals that hidden switching cost before the order is signed.
The product surface is specific enough to test
VietHosting's current commercial site does not leave the service category vague. It advertises cPanel and DirectAdmin shared hosting, reseller hosting, KVM VPS, larger VPS configurations, dedicated servers, colocation, server management, SSL certificates and server-software licences. The VPS pages describe virtual CPUs, memory, SSD storage, IPv4 assignment, domestic and international bandwidth, operating-system choices and a Virtualizor control panel. The dedicated-server pages describe processor, memory, storage, KVM-over-IP, network and address options. This is a recognisable infrastructure catalogue.
Specificity is helpful because it creates testable boundaries. A KVM VPS is not merely "cloud"; the buyer can ask how vCPU allocation is governed, whether storage performance is capped, how host failure is handled and what the control panel can do when the guest is unreachable. A dedicated server is not merely "bare metal"; the buyer can verify the processor, drive layout, remote-console access, replacement target and port profile.
A managed-server option is not the same as a fully managed application; the published management page separates basic installation and firewall tasks from paid monitoring, patching and troubleshooting.
The service pages also expose limitations that buyers often discover too late. The listed VPS packages say automatic backup is not included. Dedicated-server packages likewise do not include automatic backup. The management offering varies by tier, and the basic package is scoped to VietHosting servers or VPSs. Those statements matter more than broad claims about secure infrastructure because they locate the human work. Root access and a control panel make the customer more capable; they also leave the customer responsible for operating-system state, application security and recoverability unless another service is purchased.
Automation is visible throughout the customer journey. The account portal manages products, invoices, renewals and support tickets. The VPS panel can start, stop and reinstall systems and reset credentials. The terms say renewal invoices are generated and emailed ten days before expiry. Service is prepaid and can be suspended at expiry if payment is missing. These controls reduce routine labour for both provider and customer, but they also make account governance part of availability. A compromised portal account or missed renewal can be as consequential as a hardware fault.
An enterprise evaluation should therefore include the management planes, not only a benchmark inside the server. Can administrators enforce multifactor authentication? Can the customer create separate users and roles? Are destructive actions logged? Is console access isolated from billing access? Can support staff reset credentials, and how is identity verified? Can a customer export invoices, tickets and configuration records before leaving? The public pages demonstrate that operational automation exists. They do not fully document its access-control and audit model.
The catalogue is broad enough that the answer will vary by service. Shared hosting, unmanaged VPS, managed VPS, dedicated server and colocation place responsibility in different hands. The provider should attach a responsibility matrix to each order. Without it, a buyer may pay for infrastructure while assuming that patching, monitoring and restoration are included when the published pages place them elsewhere.
Locality is a claim with several layers
VietHosting describes its infrastructure as located in Vietnam and gives a datacentre address at Lots 27-28, Road 19, Tan Thuan Export Processing Zone, Ho Chi Minh City. The site calls the facility Tier III and says it has redundant power, network and infrastructure. The company also presents domestic bandwidth separately from international bandwidth in its VPS and dedicated-server packages. These details support a deliberately local service proposition rather than a location-free global cloud label.
They remain provider statements. The reviewed sources did not include an independent facility certification naming VietHosting, a rack-location letter, a carrier list or a customer-specific data map. A street address can identify the stated facility without proving that every service, backup, control plane and log remains there. A Tier III reference can describe a datacentre or design standard without establishing the scope of a current third-party certification. Procurement should ask for the facility operator's name, certification evidence and the exact VietHosting services covered.
Data locality is broader than server location. A production disk may sit in Ho Chi Minh City while support tickets are processed through a platform in another jurisdiction, monitoring telemetry leaves the country, payment data goes to a third party, or backups are copied elsewhere. The privacy page says VietHosting collects personal identity, contact and company information to manage accounts, process transactions, provide service and communicate with customers. The homepage and terms identify payment and support channels. None of that, by itself, provides a complete subprocessor or cross-border-transfer schedule.
The service model makes the backup location especially important. Shared hosting receives provider-managed daily and weekly copies, according to the SLA. Where those copies reside, whether they share the same failure domain and how access is controlled are not answered by the simple statement that servers are in a Vietnamese datacentre. VPS and dedicated customers are generally responsible for their own backups, which means locality can become the customer's design choice. Copying a backup to another region may improve resilience while changing sovereignty and regulatory exposure.
Local support is similarly distinct from local infrastructure. The site supplies Ho Chi Minh City addresses, Vietnamese telephone numbers, GMT+7 hours and Vietnamese-language service terms. Those are strong indicators of a Vietnam-centred customer interface. They do not disclose team size, shift coverage, escalation staffing or whether a specialist is physically present in the datacentre overnight. A 24-hour ticket channel can be continuously monitored, queued for morning review or handled through an on-call rotation; all three look identical from the contact page.
For a customer whose policy requires Vietnamese hosting or support, the contract should define each layer separately: primary compute location, backup location, log and monitoring location, account-data processing, support access location and the jurisdiction governing disclosure. "Hosted in Vietnam" is a useful headline. It is not a complete data-residency control.
Published bandwidth is a ceiling, not a constant lane
The clearest parts of VietHosting's terms are the passages that qualify its headline network numbers. VPS packages display domestic bandwidth up to 1 Gbps and international bandwidth of 32 Mbps. Dedicated-server packages display different base port figures and sell network upgrades. Several packages say traffic volume is unlimited. Read alone, those fields could be understood as a continuous per-customer promise.
The terms say otherwise, and usefully so. Shared bandwidth may be burstable. Published bandwidth in that model is a maximum limit rather than continuously maintained throughput for an individual service. If prolonged usage exceeds permitted thresholds and affects the system or other customers, VietHosting can apply traffic shaping, potentially reducing bandwidth temporarily to 10 Mbps. The terms say fixed continuous throughput is not promised unless the parties make a specific written agreement.
That wording is commercially significant. "Unlimited traffic" addresses metered volume, not guaranteed rate. A customer may be allowed to transfer data without a monthly byte cap while still sharing a port, encountering congestion or being shaped under fair-use rules. The performance of an internationally accessed application can therefore differ sharply from the impression created by a large domestic port number.
The right test is workload-shaped. A backup repository needs sustained throughput over long windows. An interactive service needs latency and low packet loss. A software mirror may produce short peaks. A video or game workload may need predictable international paths. A customer should benchmark from relevant networks at relevant times, then attach the required minimums and measurement method to the order. A speed test from one endpoint is not a service definition.
Dedicated or policy-based bandwidth is offered as a more controlled alternative. Buyers should ask whether that means a reserved access port, a committed information rate through the upstream, a routing-policy distinction or only a local shaper configuration. They should also clarify whether domestic and international traffic are measured differently, how direction is treated and how DDoS mitigation affects the committed rate.
The public terms make one particularly important point: continuous throughput requires a written agreement. That gives a buyer a clean decision. A general-purpose site may accept the shared model and lower price. A production system with a hard transfer window should pay for and document a stronger commitment. The mistake would be to buy the former while planning as if it were the latter.
The SLA contains real commitments and a material contradiction
VietHosting publishes more service-level detail than many small hosting providers. The SLA names covered services, defines downtime, describes exclusions, sets maintenance notice periods, states a support response target, distinguishes backup treatment by product, promises a dedicated-server hardware replacement target and gives a compensation table. This is substantive service-proof material. It lets a buyer identify the exact words that need to appear in an enforceable order.
The main uptime number is not internally consistent. Section 2 says Web Hosting, Reseller Hosting, KVM VPS, Dedicated Server and Colocation receive uptime of at least 99.5%. It translates that figure into 216 permitted minutes of downtime in a 30-day month. Later, the FAQ on the same page says VietHosting guarantees at least 99.9% uptime for Web Hosting, Reseller Hosting, VPS and Dedicated Server. The company introduction also displays a 99.9% claim. Those are materially different thresholds: 99.9% allows about 43 minutes in a 30-day month before exclusions, one fifth of the downtime allowed by 99.5%.
The formal numbered clause should generally carry more weight than a FAQ, but customers should not be asked to choose which public promise is operative. The signed agreement should identify one percentage, one measurement source and one scope. It should say whether the calculation applies per server, per service, per facility or across the provider, and whether partial degradation counts. It should also state the time zone and monthly boundary used.
Exclusions further shape the effective commitment. Scheduled maintenance is excluded, and the SLA says scheduled maintenance may total up to four hours per month, with 24 to 48 hours' notice. Emergency maintenance may receive as little as 15 minutes' notice. Customer configuration errors, certain software and filesystem failures, customer-side network problems, targeted denial-of-service attacks and broad force-majeure events are also excluded. These can be reasonable exclusions, but their breadth means headline uptime cannot be evaluated without incident classification.
The compensation table is useful but needs editing. It awards no compensation at 99.5% or above and then visibly moves to a 10% service-fee credit for uptime below 99.0% down to 98.5%, with larger credits at lower bands. As published, the visible table does not clearly state the treatment of service below 99.5% but at or above 99.0%. That is precisely the range immediately below the formal commitment. A customer should have the missing interval resolved in the signed schedule.
Compensation is not automatic. The customer must submit a ticket or email within seven business days after VietHosting confirms the incident has been fully resolved. The claim needs service details, timing, description and evidence. Approved compensation may be applied as added service time or by another agreed method. This puts a record-keeping burden on the customer. External monitoring, incident timestamps and retained ticket transcripts are not optional if the credit matters.
The SLA also promises hardware replacement for a dedicated server within four working hours after VietHosting confirms a qualifying failure, subject to parts availability and holiday exceptions. That starting point matters: elapsed customer impact can exceed four hours if diagnosis and confirmation take time. A production order should separate detection, acknowledgement, diagnosis, confirmation, parts replacement and service restoration. Each is a different clock.
The published document is a useful foundation, not finished enterprise assurance. Its strongest feature is that it exposes the negotiable mechanics. Its largest weakness is that the central uptime number is contradicted on the same public surface.
Support is an operating system made of people
VietHosting advertises technical support around the clock through hotline, ticket and email, while listing ordinary telephone hours of 07:30 to 18:00 from Monday to Saturday in GMT+7. Its terms direct sensitive security issues and complex technical incidents to tickets or email so that the work can be tracked. The company page calls tickets the official and preferred channel for technical requests. This is a sensible operating model: an auditable queue is usually more reliable than an undocumented phone conversation.
The response promises still need reconciliation. The SLA commits to an initial response to tickets and email within a maximum of four hours, with wording that excludes Vietnamese public holidays. The FAQ says technical tickets are normally answered in roughly 15 to 30 minutes, sales questions in business hours and emergencies immediately. The latter is a service aspiration; the former is the closer thing to a contractual ceiling. A buyer should plan around four hours unless a stronger incident-specific target is written into the order.
Initial response is not resolution. A quick acknowledgement can satisfy a response metric while diagnosis, escalation and recovery take much longer. The public document does not give severity definitions, restoration targets or a named escalation ladder. It does not say when an incident reaches a network engineer, systems administrator, datacentre technician or management representative. It does not publish historical attainment against the four-hour target.
The support burden also depends on the product. In shared hosting, VietHosting controls more of the stack and promises provider-run backup copies. In an unmanaged VPS or dedicated server, the customer controls the operating system and application. A provider can restore network or hardware while the customer's service remains broken because its filesystem, firewall or software failed. The support team must first locate the boundary, which makes clean logs and an accurate responsibility matrix essential.
Local labour is part of the value proposition. Vietnamese language, GMT+7 operations, domestic published contact points and a Ho Chi Minh City working address can reduce coordination cost for local customers. That advantage should be measured through actual incidents: time to useful acknowledgement, number of handoffs, technical accuracy, access to a decision-maker and quality of the final incident explanation. A phone number proves reachability; it does not prove depth.
A trial should include more than a polite sales ticket. Before moving production, a buyer can test an after-hours technical ticket, an account-verification request, a reverse-DNS change, a restore question and an escalation. The goal is not to manufacture failure. It is to see whether the support system preserves context and ownership when the question crosses billing, network and server teams. Hosting assurance lives in that handoff.
Backup language redraws the risk boundary
The SLA draws a sharp line between shared hosting and customer-controlled compute. Web Hosting and Reseller Hosting receive automated daily and weekly backups, with newer copies overwriting older copies of the same type. Daily backup is usually scheduled between 03:00 and 05:00 GMT+7. The copies are primarily described as protection for serious provider hardware or infrastructure incidents, and customers are still told to maintain their own important backups.
KVM VPS, Large VPS, dedicated servers and colocation do not include automatic periodic backup unless a separate backup service is agreed. Customers are responsible for managing and performing their own copies. The homepage gives the same distinction in shorter form: shared hosting retains the nearest daily and weekly backups, while VPS and dedicated customers with administrative control must arrange backup themselves unless they buy the service.
This is one of the most important disclosures on the site. RAID-10, enterprise SSDs and a stable datacentre are not backups. They may improve availability or tolerate some component failure, but they do not protect against administrative deletion, compromised credentials, corrupted data replicated across disks or a destructive application event. A customer buying a VPS without a separate recovery design is buying compute, not recoverability.
Even shared-hosting customers need to understand the copy model. One daily and one weekly generation provide a short history. An error or compromise that remains undetected can enter both generations. The public text does not state a restore-time objective, restore-point guarantee, separate failure domain, immutability control or customer self-service export method. It promises that VietHosting will make its best effort to restore from the nearest available copy if technically possible, not that every requested point can be recovered.
The lifecycle terms raise the stakes. Service is prepaid. The terms say an unpaid service can be suspended at expiry and related data may be permanently deleted seven days later. Cancellation also leads to permanent deletion of the associated data. Those rules are operationally understandable for a hosting provider, but the window is short for a customer with slow procurement or an employee transition. Renewal automation and billing alerts become continuity controls.
Free migration support can reduce switching cost on the way in. It does not remove the need for an exit plan. Before cutover, the customer should prove that it can export data, configuration, DNS records, certificates, logs and account evidence without provider intervention. It should hold an independent copy in a different administrative account and, where the risk warrants it, a different provider or facility. The best restore test is one completed before the original system is unavailable.
Security claims are bounded by shared responsibility
VietHosting explicitly uses a shared-responsibility model. The provider says it protects server, network and datacentre infrastructure, while customers protect applications and data through strong credentials, updates and access management. This is a more credible framing than an undifferentiated promise that hosted data is simply secure. It acknowledges that a provider cannot patch a customer application it does not manage.
The product pages name controls and technologies such as firewalls, Imunify360, cPanel, DirectAdmin, CloudLinux and virtualisation panels. The management service offers firewall setup, patching, monitoring and troubleshooting at different levels. These are capabilities, not proof of universal deployment or correct configuration. A customer needs to know which control is included in its exact plan, who maintains it and what evidence can be supplied after an incident.
The SLA's DDoS language is notably restrained. It says the infrastructure has basic firewall and mitigation capability, but no system can provide absolute protection. If attack traffic exceeds physical bandwidth, a server may be null-routed or interrupted to protect the wider system. The SLA excludes targeted DoS or DDoS against a customer's website or address from uptime compensation and suggests a specialised proxy or application-layer service for customers with elevated exposure.
That boundary is commercially rational, but it changes the security purchase. A customer at risk of extortion or high-volume attack should not treat the hosting plan as managed DDoS protection. It needs detection thresholds, scrubbing arrangements, null-route policy, communications procedure and recovery conditions in writing. It should also know whether the provider can announce a more specific route, move an address or coordinate with its upstream during an event.
Account security remains another public gap. The terms require customers to safeguard credentials and notify VietHosting of unauthorised access. The reviewed pages did not provide a detailed public description of multifactor authentication, privileged support access, access logs or staff approval controls. Their absence from the pages does not mean the controls are absent. It means they require direct verification before a sensitive workload relies on the portal.
The privacy page confirms that personal identity, contact and company information may be collected for account management, transactions, service delivery and communications. That is expected for a paid infrastructure service. A business customer should go further and ask for retention periods, support-access logging, processor details, breach notification terms and deletion evidence. The more administration the provider performs, the more clearly those duties should be defined.
The buyer's evidence schedule
The public record is strong enough to support a focused diligence request. It does not require a speculative investigation or a large questionnaire. The first page should reconcile identity. It should name VIET HOSTING COMPANY LIMITED, tax identifier 0313752826; VietHosting Solutions Company Limited, tax identifier 0318129340; the VietHosting brand; AS140781; and 103.161.212.0/23. For each, the provider should identify owner, operator, contracting role and current authority.
The second page should define the selected service. It should state whether the order is shared hosting, reseller hosting, unmanaged VPS, managed VPS, dedicated server or colocation; list included resources and controls; name excluded functions; and identify every optional service being purchased. Marketing families should give way to a bill of service. "Managed" needs a task list, hours and escalation target.
The network schedule should state the assigned addresses, route origin, upstream design, domestic and international bandwidth model, committed and burst rates, shaping triggers, reverse-DNS process, RPKI responsibility and failover method. If AS140781 is not the production origin for the selected service, the schedule should identify the actual network. If the customer needs IPv6, the assignment and test method should be explicit.
The locality schedule should identify the facility operator and address, primary storage location, backup location, management-plane location, monitoring location and support-access geography. It should distinguish a provider assertion of Tier III hosting from the exact certificate and scope. It should list subprocessors and describe cross-border transfers where relevant.
The reliability schedule should resolve the 99.5% and 99.9% conflict. It should define availability measurement, exclusions, maintenance limits, claim windows and the missing compensation band. For dedicated hardware, it should define when the replacement clock starts and what temporary alternatives exist. For every product, it should set severity levels, initial response, update frequency, restoration objective and escalation contacts.
The backup schedule should name frequency, retention, isolation, encryption, restore method, restore target and test cadence. If the customer owns the duty, the architecture should show where the independent copies go and who monitors failed jobs. If VietHosting supplies the service, the order should say whether the provider's copy survives account compromise and whether the customer can retrieve it without opening a support ticket.
Finally, the exit schedule should state notice periods, export formats, address portability, DNS responsibilities, final backup access, deletion timing and evidence of deletion. The public terms allow data deletion soon after expiry, so the customer's internal renewal process should have multiple owners and an emergency payment route. Low monthly cost does not justify a brittle exit.
None of these requests is exotic. They translate the provider's own public statements into a service that can be operated. A small customer may accept lighter documentation. An organisation placing a revenue-bearing or regulated system on the platform should not rely on the brand name to fill the gaps.
Where the commercial value can be real
VietHosting's proposition has several plausible advantages. A Vietnam-centred provider can offer local-language coordination, domestic payment methods, a Ho Chi Minh City operating presence and bandwidth packaged for domestic access. The product catalogue covers a path from low-cost hosting to VPS, dedicated servers, colocation and management. A customer can keep procurement and support with one supplier while increasing control over the stack.
The automation surface can also remove routine work. Self-service provisioning, operating-system installation, console access, invoice generation, renewal reminders and ticket tracking reduce the number of manual exchanges required to keep a server running. Free migration assistance can lower the initial labour cost. Optional management can shift patching, troubleshooting and monitoring tasks to a team that works with the platform daily.
The trade-off is supervision. Someone still has to govern access, review invoices, monitor backups, test restores, interpret bandwidth, maintain applications and decide when support has crossed a severity threshold. If the service is unmanaged, much of the systems work stays with the customer. If it is managed, the customer must verify that the paid task list matches the operational need. Automation does not abolish labour; it changes the labour from repetitive execution to exception handling and accountability.
Network concentration may be acceptable for a modest local workload with an independent backup and a tested recovery plan. It may be unacceptable for a service that cannot tolerate one upstream relationship or one facility region. The answer depends less on the size of AS140781 than on the workload's failure budget. A buyer should compare the full design cost, including secondary DNS, external monitoring, backup storage, DDoS protection, support supervision and migration, rather than compare server prices alone.
The legal-name issue belongs in that cost calculation. If VietHosting promptly documents the relationship between the older resource holder and the newer contracting company, the issue may be administrative. If it cannot, the buyer carries uncertainty at every escalation point. The cheapest way for the provider to increase trust is not necessarily more infrastructure. It is a clear statement of who controls what.
Operating assurance begins where the name stops
VIET HOSTING COMPANY LIMITED is not a hollow entry. Its public identity connects to a Vietnamese legal record, an official historical registrar list, APNIC number resources, a live BGP announcement and a long-running commercial brand. AS140781 and its /23 provide specific, current evidence that can be checked independently. The VietHosting website provides a real catalogue and more operational detail than a buyer would get from a bare registry record.
The evidence also sets firm limits. One visible IPv4 prefix does not establish route diversity. A valid ROA does not establish server security. A Ho Chi Minh City datacentre address does not map every copy of customer data. A 24-hour ticket channel does not define resolution. A daily backup statement does not replace a restore test. A brand history does not explain a legal succession.
Most of all, the company name on the network records is not the company name in the current SLA. Shared address, contact and brand details make a relationship highly plausible, but operating assurance requires the relationship to be explicit. The current provider should be able to show its authority to operate the resources, its responsibility for the service and its accountability for customer data without asking the customer to infer a transfer.
The published service terms offer a constructive starting point. They acknowledge shared bandwidth, shaping, product-specific backup limits, DDoS boundaries and customer responsibility. Those candid limitations are more valuable than an unqualified promise of perfect infrastructure. Yet the 99.5% versus 99.9% uptime conflict and the unclear compensation interval show why public copy must be converted into a controlling service schedule.
For a buyer, the decision is not whether VietHosting looks like a hosting company. The records establish that it has a genuine hosting and network surface. The decision is whether the selected product, legal provider, route, data location, support team and recovery plan form one accountable system. Once those elements are written down and tested, the name can carry assurance. Until then, it is the beginning of diligence, not its conclusion.

