WHO OWNS THE SERVER, OWNS THE RISK?
India’s Hosting Economy, Domain Security and the Case for Data Sovereignty
An Editorial Investigation by Chapde News | Technology, Information Practices & Digital Governance Desk
By the Chapde News Investigative Desk
Editorial draft — allegations involving individuals require documentary verification before publication.
The question India can no longer afford to ignore
India has built one of the world’s largest digital economies, yet a surprisingly simple question remains uncomfortable: Who ultimately controls the infrastructure on which India’s entrepreneurs store their identities, websites, customer databases, intellectual property and digital businesses?
For a small entrepreneur, a domain may look like a yearly subscription. For a technology company, however, a domain can represent a brand, customer acquisition channel, intellectual property and millions of rupees in accumulated business value.
A VPS is not merely a rented computer. A control panel is not merely a dashboard. A registrar account is not merely a login.
Together, they form a digital chain of custody.
And when that chain fails—through hacking, credential compromise, insider abuse, poor account governance, social engineering or operational mistakes—the entrepreneur can lose far more than a website.
That is why India’s hosting and domain industry deserves scrutiny not as a battle between brands, but as a matter of data security, digital governance and consumer protection.
The GoDaddy question: documented security incidents versus unverified allegations
GoDaddy is one of the world’s largest domain and hosting companies and has a substantial presence among Indian entrepreneurs.
But responsible journalism must distinguish between documented facts and allegations.
GoDaddy’s own regulatory filings disclose significant historical cybersecurity incidents. Its filings state that in 2020, hosting login credentials of approximately 28,000 hosting customers were compromised, with more than 5,000 additional affected customers subsequently identified. The company also disclosed a 2021 Managed WordPress incident involving up to 1.2 million active and inactive customers. In December 2022, GoDaddy reported unauthorized access to cPanel hosting servers and malware that intermittently redirected random customer websites.
Those are not allegations from a competitor. They are disclosures contained in GoDaddy’s own regulatory reporting.
But there is an equally important journalistic boundary.
Chapde News has not independently established the allegation that GoDaddy employees stole particular Indian customers’ domains, nor has it established the allegation concerning an individual identified as “Sumit Kharab.”
Likewise, claims that particular employees were corrupt, that specific domains were deliberately “mortgaged,” or that company personnel protected certain domains while allowing others to be lost should not be published as established facts without documentary evidence, complaints, transaction records, registrar logs, court records, police records, internal correspondence or a response from the company and the individuals concerned.
That distinction is not a technicality.
It is journalism.
The Yogesh Gupta case: a warning that demands evidence
The case presented to Chapde News describes an alleged dispute involving an Indian entrepreneur, Yogesh Gupta, who allegedly lost control of important domains and projects while using hosting/registrar infrastructure.
The allegations further raise questions about employee access, domain custody, account administration and whether commercially important digital assets received different treatment from ordinary customer assets.
These claims deserve investigation—but they should initially be treated as a case study and allegation requiring verification, rather than as a proven finding of criminal conduct.
The investigative questions are nevertheless important:
- Who was the registered domain holder?
- Which email address controlled the registrar account?
- Who possessed administrative or delegate access?
- Were two-factor authentication and transfer locks enabled?
- Were domain ownership changes recorded?
- Was an EPP/authentication code generated?
- Were DNS records altered?
- Were nameservers changed?
- Was there an account-transfer event?
- What IP addresses accessed the account?
- Were support tickets opened?
- Which employee or support channel handled them?
- Does an audit trail exist?
- Was the domain transferred, expired, deleted, suspended or merely inaccessible?
- Were backups maintained independently?
- Did the customer have contractual evidence establishing ownership?
These questions can transform an emotional domain dispute into a forensically testable technology investigation.
The uncomfortable lesson: a domain is an asset
India’s entrepreneurs frequently underestimate their domains.
A domain can represent:
Brand + SEO equity + customer traffic + email identity + intellectual property + advertising investment + customer trust + business continuity.
If a company has spent ten years building a brand around one domain, its replacement value may be far greater than its registration fee.
This is why domain security should be treated similarly to other corporate assets.
A founder should never assume:
“The hosting company has my domain, so the hosting company will protect it.”
The registrar is a service provider.
The entrepreneur remains responsible for establishing ownership, access control, recovery mechanisms and evidence.
GoDaddy: the strength and the warning
GoDaddy’s biggest strength is also part of the reason it deserves serious scrutiny: scale.
It provides domains, hosting, WordPress services, security products and other digital infrastructure under one ecosystem.
That convenience can be extremely valuable to entrepreneurs.
GoDaddy also provides domain transfer locks and additional domain-protection mechanisms. Its documentation says domain transfer locks can prevent unauthorized transfers, while stronger protection can require identity verification for sensitive account changes.
But the company’s documented cybersecurity history demonstrates a broader lesson:
Size does not equal immunity.
The existence of sophisticated security controls does not mean an organization is incapable of suffering credential compromise, unauthorized access or infrastructure attacks.
For Indian businesses, the correct question is therefore not:
“Is GoDaddy secure?”
It is:
“Which security controls does GoDaddy provide, which controls remain the customer’s responsibility, and what independent evidence exists when ownership is disputed?”
HostGator: the infrastructure-first alternative
HostGator occupies a different position in this discussion.
Its Indian operation has historically emphasized local infrastructure and support. HostGator’s documentation states that its Indian operation uses servers in India and Singapore and operates separately from its U.S. service infrastructure, with Indian support staff serving Indian customers.
Its Indian VPS offering provides full root access, allowing administrators to control the server environment and install their own software.
HostGator also documents its use of firewall rules, mod_security protections and network-level flood protection.
That makes HostGator particularly relevant for developers and organizations that want greater control over their server environment.
But control brings responsibility.
A root account in the wrong hands is not a security advantage.
It is a master key.
HostGator itself acknowledges that vulnerable passwords, outdated software and application vulnerabilities can still compromise customer environments.
The company also continues to use cPanel in its VPS ecosystem and offers WHMCS licensing for VPS customers.
Hostinger: the new-generation challenger
Hostinger represents a somewhat different philosophy.
Rather than making traditional cPanel administration the center of its entire ecosystem, Hostinger has developed its own hPanel environment.
Its technology documentation describes an infrastructure incorporating hPanel, CloudLinux, LiteSpeed, Cloudflare integration, an in-house WAF, backups, account isolation and DDoS-related protections.
Hostinger also offers VPS products where customers can select server locations, including India, subject to current availability.
For developers who specifically want cPanel, Hostinger also offers cPanel VPS hosting, including automatic backups and malware-scanning features.
This creates an interesting distinction:
GoDaddy
Best understood as a broad digital-services ecosystem where domains, hosting and business products can be managed together.
HostGator
Strong appeal for users who want conventional hosting infrastructure, cPanel and VPS/root-access administration.
Hostinger
Strong appeal for users who want a modern, integrated hosting platform with its own control environment and competitively priced VPS infrastructure.
None should automatically be labelled “the safest.”
Security depends upon architecture, configuration, access management, employee controls, monitoring, backups and—critically—the customer’s own security practices.
cPanel and WHMCS: the hidden layer behind the hosting business
The hosting industry also needs to explain something many entrepreneurs never see.
Behind a familiar hosting dashboard can sit an ecosystem involving:
Server → Operating System → Virtualization → Web Server → cPanel/alternative panel → WHM → DNS → SSL → Billing → WHMCS → Registrar → Backup → Monitoring → Security layer.
cPanel and WHM are widely used technologies, while WHMCS can automate hosting billing and customer management.
But the frequently repeated claim that establishing a cPanel/WHMCS environment necessarily costs ₹5–6 crore should not be presented as a universal industry fact without a detailed quotation and scope.
The cost can vary enormously depending on whether someone is discussing:
- software licensing,
- server infrastructure,
- data-centre deployment,
- networking,
- redundancy,
- security,
- engineering salaries,
- support operations,
- billing integration,
- custom development,
- disaster recovery,
- compliance,
- or an entire commercial hosting operation.
The distinction is crucial.
A control panel is software. A hosting company is infrastructure plus operations plus security plus people.
The real Indian problem: concentration of digital infrastructure
The bigger story is not GoDaddy versus HostGator versus Hostinger.
It is concentration risk.
When millions of websites depend upon a relatively small number of technology providers, a vulnerability, outage, compromised credential, DNS failure, ransomware incident or operational error can potentially affect enormous numbers of businesses.
This is why India should encourage a stronger ecosystem of:
- Indian data centres,
- geographically distributed VPS infrastructure,
- sovereign cloud capabilities,
- independent backup providers,
- redundant DNS,
- secure registrar services,
- Indian cybersecurity operations,
- domestic incident-response capabilities,
- cryptographic identity systems,
- hardware-backed authentication,
- transparent audit logs,
- and interoperable infrastructure.
The objective should not be to isolate India from the global Internet.
The objective should be:
India should never become dependent upon a single digital gatekeeper.
Data sovereignty is not the same as server location
There is another misconception worth correcting.
Putting a server physically in India does not automatically make every aspect of a business’s data ecosystem “sovereign.”
Data can move through:
DNS providers → CDNs → email systems → analytics → payment gateways → SaaS platforms → support systems → backups → monitoring platforms → third-party APIs.
Therefore, information security must examine the entire data lifecycle, not merely the physical location of the VPS.
For sensitive organizations, the question should be:
Where is the data stored, who can access it, where are the backups, where are logs stored, who controls encryption keys, and what happens when the service provider receives a legal or operational request?
The journalist’s test: follow the data, not the advertisement
A technology journalist should not judge hosting companies by promotional slogans.
The newsroom test should be:
1. Ownership
Who legally owns the domain?
2. Authentication
How many independent authentication factors protect it?
3. Authorization
Who has administrative access?
4. Auditability
Can every important action be traced?
5. Redundancy
Does the business have independent backups?
6. Recovery
Can the customer recover without the original hosting provider?
7. Portability
Can the website and domain be moved elsewhere?
8. Transparency
Does the provider disclose security incidents?
9. Infrastructure
Where are the servers and backups located?
10. Human security
How are privileged employees and support personnel controlled?
That final question may be the most important.
Because the strongest firewall can still be defeated by a compromised administrator account.
The HostGator lesson: segmentation matters
HostGator’s documentation provides an interesting security architecture example: it states that HostGator.com and HostGator India use separate support staffs and different data centres, and that staff on one side do not have access to the other’s servers.
That principle—least privilege and administrative segmentation—deserves far wider adoption.
If an employee does not need access to a customer’s server, that employee should not have it.
If a support employee can reset a password, the reset should generate an immutable audit record.
If an administrator can transfer a domain, high-value domains should require additional verification.
If one employee can approve and execute a sensitive operation alone, the organization should consider four-eyes authorization.
The domain-security doctrine India needs
Chapde News proposes a simple principle:
No single human should be able to steal a digital business.
For high-value domains, registrars and hosting companies should encourage:
Two-factor authentication
Registrar lock
Hardware security keys
Independent recovery email
Separate administrative account
Domain ownership documentation
Change alerts
DNS monitoring
Independent backups
Emergency registrar contact
Immutable audit logs
Multi-person authorization for critical changes.
GoDaddy itself recommends 2-step verification and provides additional controls around domain changes and transfers.
These mechanisms should become standard practice across the industry.
A word to Indian entrepreneurs
Do not keep your entire digital business inside one login.
Your domain, hosting, email, website, database and backups should not all depend upon one password, one employee or one vendor.
Maintain:
Registrar account → independently protected
Hosting account → independently protected
Email → independently protected
DNS → independently monitored
Database → independently backed up
Source code → independently backed up
Customer data → securely backed up
Critical credentials → securely escrowed
The objective is simple:
If your hosting company disappears tomorrow, your business should still exist.
The final verdict
GoDaddy, HostGator and Hostinger should not be reduced to simplistic labels such as “good” or “bad.”
Each has meaningful strengths.
GoDaddy demonstrates the scale and convenience of an integrated domain-and-hosting ecosystem, while its own regulatory disclosures also demonstrate that even a major technology provider can experience serious cybersecurity incidents.
HostGator provides a more traditional infrastructure model, including cPanel, VPS/root access and Indian hosting options, making it attractive to administrators who want greater server-level control.
Hostinger brings a modern control-panel model through hPanel while also offering cPanel VPS products, geographically distributed infrastructure and security features such as backups, malware scanning and firewall capabilities.
But none of these platforms should become an entrepreneur’s single point of failure.
The Chapde News editorial position
India does not need a war against foreign hosting companies.
India needs accountability, competition, transparency and technological sovereignty.
The right question is not:
“Which company should India hate?”
The right question is:
“How can India build a digital infrastructure in which no registrar, hosting company, employee, hacker, administrator or government system can silently become the sole custodian of an entrepreneur’s digital identity?”
The alleged Yogesh Gupta case—if supported by documentary evidence—could become more than a dispute over domains.
It could become a case study in digital asset governance.
And if the allegation involving Sumit Kharab is to enter the public record, it must enter through evidence, not insinuation.
That is where responsible technology journalism begins.
Because in the digital economy, a domain is not merely a web address.
It can be a business.
It can be a reputation.
It can be intellectual property.
It can be a livelihood.
And ultimately—
It can be an Indian digital asset that deserves protection.
— Chapde News | Technology, Information Practices & Digital Governance Desk
Editorial note: This article intentionally distinguishes verified public records from allegations supplied for investigation. Before publication, Chapde News should seek documentary evidence and written responses from the affected individuals, GoDaddy, HostGator/its relevant Indian operating entity, and any other parties named in the underlying dispute.