Rack1 Networks
Hosting
Basic Shared Web HostingAccelerated Web HostingStatic Web HostingWordPress Optimized Hosting Managed Cloud (coming soon) Compare all plans
AI Chatbots
AI Chatbots for your site
Platform
The Rack1 Platform Our control panel Security Edge CDN One-click installer
Company
Blog About Rack1 Documentation Support Acceptable Use Policy View plans
Security

Security is a platform job,
not a plugin you install

Most sites get compromised through something the owner was supposed to be watching. We would rather that job sat with us, so everything below is switched on for every account from the moment it is created, with nothing for you to configure, renew or remember.

  • Scanned every day
  • Firewalled at the edge
  • Free SSL on everything
  • Included on every plan

Automatic malware scanning

Every site on the platform is scanned every day using a combination of commercial engines and our own tooling, and you can run a scan on demand rather than waiting for the next one.

WordPress sites get an extra check: core files are compared against the official release to catch anything that has been quietly modified. If malware is found, outgoing PHP mail is disabled automatically so your site cannot be used to infect anyone else while you clean up.

Multi-factor authentication

Multi-factor authentication is supported on our control panel and on shell access, using time-based one-time codes from any standard authenticator app: Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden or whatever you already use.

A password on its own is one stolen laptop away from being someone else's password. Turning this on is the single most effective thing you can do for your account, and it takes about a minute.

Web application firewall

Requests are inspected at the edge of the network, in well under a millisecond, for SQL injection, cross-site scripting, path traversal, trojans and a long list of other attacks.

Rules come from commercial threat feeds and from custom rules written for the platform, so it keeps up without you patching anything.

DDoS absorption

Over 1 Tbps of anti-DDoS capacity sits in front of the platform, filtering malicious traffic while legitimate visitors carry on unaffected.

Combined with Rack1 Burst adding compute as demand climbs, an attack is far more likely to be something we tell you about afterwards than something you notice.

Brute-force protection

Login attempts are monitored across WordPress and other common application logins, and automated attempts are challenged before they ever reach your site.

Suspicious addresses and networks are reputation-scored at the network edge, and bad ranges are blocked outright rather than politely rate-limited.

Credentials never travel in the clear

Every service that asks for a password speaks its encrypted variant. Mail runs over IMAP, POP3 and SMTP with TLS; file transfer is SFTP or FTPS; shell access is SSH; and the control panel and webmail are HTTPS only.

We use the secure versions of these protocols rather than offering the plaintext ones alongside them, so your password is never sent across the network in the clear for someone on the same coffee shop network to read.

Patched without you asking

Operating systems, web servers, PHP releases and database servers are patched on the platform as security fixes land. There is no maintenance window you have to remember and no version you are quietly left behind on.

The one part that stays yours is your own application and its plugins, which is the gap worth watching.

Separated server roles

Web servers serve websites, database servers run databases and mail servers handle mail. They are separate stacks, not one machine doing everything.

Logging is centralised away from those servers, so an intruder on one cannot cover their tracks or read your mail from it.

None of this needs switching on

There is no security plugin to install, no agent to run, no add-on to buy and no dashboard to learn. Everything on this page is part of the platform itself, active from the moment your account is created, on every plan we sell.

Nothing to installNo plugin, no agent, no third-party service to sign up for and wire in.
Nothing to configureScanning, firewalling and filtering are already running when you first log in.
Nothing to renewCertificates reissue themselves and firewall rules update without you tracking a date.
Nothing extra to payIncluded on every plan, from the $2.99 one upwards. None of it is a premium tier.

Controls you hold yourself

Everything above runs whether you think about it or not. These are the ones you can reach for when you need them, all from our control panel.

  • Closed by default. SFTP, remote MySQL and shell access stay denied until you switch them on, and can re-lock themselves automatically afterwards.
  • Block by address or country when something is causing you trouble, without writing a rule by hand.
  • Password-protect any folder in a couple of clicks, with no code involved.
  • File permissions checker that finds permissions which are wrong or dangerously loose, and tells you what they should be.
  • Security headers such as CSP and HSTS, set from the panel rather than hand-edited into a config file.
  • Free SSL on everything, issued and renewed automatically for every domain and subdomain, with transfers secured in transit.

Mail, scanned on the way in and out

Email is how most trouble arrives, and how a compromised site does most of its damage.

  • Commercial deny lists from established anti-spam providers, applied at the network level before a message is accepted.
  • Virus signature scanning, with known malware rejected rather than delivered to a folder.
  • Content filtering into junk mail, with allow and deny lists you control from webmail.
  • Rejected, not swallowed. Blocked mail is returned to the sender so a legitimate correspondent finds out, rather than vanishing silently.
  • Outgoing mail is monitored too, under a zero-tolerance spam policy, which is how we notice a compromised site quickly.

Backups that survive a bad day

Backups follow the 3-2-1 principle: each server stack keeps its own redundant local copies, and a full set is written to a separate data centre so a disaster in one place does not take your recovery option with it.

The buildings your site sits in

We partner with reputable, well-established data centre and network providers, and we only use facilities that meet a serious physical security standard:

  • Security staff on site, around the clock
  • Photo ID and swipe card entry, with gated access and secure perimeter fencing
  • CCTV coverage inside and out
  • Redundant and uninterruptible power

Independently accredited

The platform and facilities behind your site are audited by third parties rather than self-certified. Staff access follows least-privilege and need-to-know policies, centrally managed.

ISO 27001ISO 9001ISO 22301 SOC 2 Type 2Cyber Essentials Third-party hosting security accreditation

These accreditations are held by the infrastructure and platform partners we build on. We are naming what is behind your site rather than claiming a certificate of our own.

Being straight with you

What we cannot protect you from

A security page that only lists wins is a sales page. These are the gaps that stay yours no matter how good the platform is, and knowing about them is most of the battle.

Still your responsibility

  • Your credentials. If someone gets your control panel or SFTP login, the platform will helpfully do whatever they ask. Use a password manager and turn on multi-factor authentication.
  • Your application and its plugins. We scan for malware and block a great deal at the edge, but an out-of-date plugin with a known hole is still an open door. Update things.
  • What you install. A theme or plugin from an unknown source can be malicious on the day you install it, before any scanner has seen it.
  • Third-party JavaScript. Anything you embed from someone else's domain runs in your visitors' browsers with your site's privileges.
  • Your domain registrar. DNS is a separate account to look after, and it is worth locking down as carefully as your hosting.

Hosting that looks after itself.

Every protection on this page is included on every plan, from the $2.99 one upwards. Nothing here is an add-on.