Hosting Security

Security that runs quietly in the background.

Most people never think about the server their site sits on until the day it breaks. Our job is to make sure that day doesn't come. Here is the shape of how we keep the sites we host defended, without making it your problem to manage.

Defence in depth

No single control catches everything, so we layer several.

Security is not one product you switch on. It is a series of layers, each covering the gaps in the one before it. If an attack slips past the first, the next is there to catch it. Here is how those layers stack up for the sites we host.

The layers
Layer 01

The edge

Traffic is filtered before it reaches the server.

  • A global edge network sits in front of every site.
  • Denial-of-service floods and obvious junk traffic are absorbed out there, not on your server.
  • Legitimate visitors get a faster site as a side effect.
Layer 02

The firewall

Our own WAF inspects every request that gets through.

  • We run our own web application firewall, tuned for the platforms and plugins we host.
  • It blocks known attack patterns, so common exploits never reach the site.
  • When a new vulnerability appears, we can block it here quickly while the official fix rolls out.
Layer 03

The server

Hardened, access-controlled, and kept current.

  • Sites are isolated so a problem with one does not spread to the others.
  • Administrative access is locked down and kept to the people who need it.
  • The stack is patched and kept up to date rather than left to drift.
Layer 04

Monitoring and response

Someone is watching, and repeat offenders get shut out.

  • Uptime and server health are monitored around the clock.
  • Addresses that keep probing or brute-forcing get blocked automatically.
  • We get alerted when something looks off, and we act on it.
Layer 05

Backups and recovery

When the worst happens, we can undo it.

  • Automated daily backups are stored away from the server.
  • Because they live off the server, they cannot be encrypted or wiped along with it.
  • Restores are straightforward, so a bad day becomes a rollback rather than a rebuild.
What this means for you

The point of all of it is a quieter life.

Fewer incidents

Most attacks are automated and go looking for easy targets. Layered defence means the sites we host are not the easy target.

Faster patching

When a serious vulnerability drops, we can block the attack at the firewall within hours and patch underneath it, rather than waiting for a scheduled update.

Backups that actually work

Backups are only useful if they restore. Ours are kept off-server and are quick to bring back, so recovery is measured in minutes, not days.

No surprises for your clients

For agencies, all of this runs under your brand. Your clients see a site that stays up and stays clean, and they see you keeping it that way.

A note on specifics

We don't publish exactly how it's configured, and that's on purpose.

You'll notice this page describes what we do without listing the exact rules, thresholds, and settings behind each layer. That is deliberate. Publishing the specifics of a security setup mostly helps the people trying to get through it.

If you're an agency weighing us up as a hosting partner, that is a fair thing to want detail on. We are happy to walk you through how it works properly, under an NDA, so you can make the call with your eyes open.

FAQ

Common questions about hosting security.

Can't find what you're looking for? Get in touch and we'll be happy to help.

Contact us

Questions about how we secure it?

If you're weighing us up as a hosting partner, we're happy to talk through the detail under an NDA.