Security is a platform job, not a plugin you install
Most sites get compromised through something the owner was
supposed to be watching. We would rather that job sat with us, so everything below is switched on for
every account from the moment it is created, with nothing for you to configure, renew or remember.
Scanned every day
Firewalled at the edge
Free SSL on everything
Included on every plan
Automatic malware scanning
Every site on the platform is scanned every day using a combination of commercial engines and
our own tooling, and you can run a scan on demand rather than waiting for the next one.
WordPress sites get an extra check: core files are compared against the official release to
catch anything that has been quietly modified. If malware is found, outgoing PHP mail is
disabled automatically so your site cannot be used to infect anyone else while you clean up.
Multi-factor authentication
Multi-factor authentication is supported on our control panel and on shell access, using
time-based one-time codes from any standard authenticator app: Google Authenticator, Microsoft
Authenticator, Authy, 1Password, Bitwarden or whatever you already use.
A password on its own is one stolen laptop away from being someone else's password. Turning
this on is the single most effective thing you can do for your account, and it takes about a
minute.
Web application firewall
Requests are inspected at the edge of the network, in well under a millisecond, for SQL
injection, cross-site scripting, path traversal, trojans and a long list of other attacks.
Rules come from commercial threat feeds and from custom rules written for the platform, so it
keeps up without you patching anything.
DDoS absorption
Over 1 Tbps of anti-DDoS capacity sits in front of the platform, filtering malicious traffic
while legitimate visitors carry on unaffected.
Combined with Rack1 Burst adding compute as demand climbs, an attack is far more likely to be
something we tell you about afterwards than something you notice.
Brute-force protection
Login attempts are monitored across WordPress and other common application logins, and automated
attempts are challenged before they ever reach your site.
Suspicious addresses and networks are reputation-scored at the network edge, and bad ranges are
blocked outright rather than politely rate-limited.
Credentials never travel in the clear
Every service that asks for a password speaks its encrypted variant. Mail runs over IMAP, POP3
and SMTP with TLS; file transfer is SFTP or FTPS; shell access is SSH; and the control panel and
webmail are HTTPS only.
We use the secure versions of these protocols rather than offering the plaintext ones alongside
them, so your password is never sent across the network in the clear for someone on the same
coffee shop network to read.
Patched without you asking
Operating systems, web servers, PHP releases and database servers are patched on the platform
as security fixes land. There is no maintenance window you have to remember and no version you
are quietly left behind on.
The one part that stays yours is your own application and its plugins, which is the gap worth
watching.
Separated server roles
Web servers serve websites, database servers run databases and mail servers handle mail. They
are separate stacks, not one machine doing everything.
Logging is centralised away from those servers, so an intruder on one cannot cover their tracks
or read your mail from it.
None of this needs switching on
There is no security plugin to install, no agent to run, no add-on to buy and no dashboard to
learn. Everything on this page is part of the platform itself, active from the moment your account
is created, on every plan we sell.
Nothing to installNo plugin, no agent, no third-party service to sign up for and wire in.
Nothing to configureScanning, firewalling and filtering are already running when you first log in.
Nothing to renewCertificates reissue themselves and firewall rules update without you tracking a date.
Nothing extra to payIncluded on every plan, from the $2.99 one upwards. None of it is a premium tier.
Controls you hold yourself
Everything above runs whether you think about it or not.
These are the ones you can reach for when you need them, all from our control panel.
Closed by default. SFTP, remote MySQL and shell access stay denied until you switch them on, and can re-lock themselves automatically afterwards.
Block by address or country when something is causing you trouble, without writing a rule by hand.
Password-protect any folder in a couple of clicks, with no code involved.
File permissions checker that finds permissions which are wrong or dangerously loose, and tells you what they should be.
Security headers such as CSP and HSTS, set from the panel rather than hand-edited into a config file.
Free SSL on everything, issued and renewed automatically for every domain and subdomain, with transfers secured in transit.
Mail, scanned on the way in and out
Email is how most trouble arrives, and how a compromised
site does most of its damage.
Commercial deny lists from established anti-spam providers, applied at the network level before a message is accepted.
Virus signature scanning, with known malware rejected rather than delivered to a folder.
Content filtering into junk mail, with allow and deny lists you control from webmail.
Rejected, not swallowed. Blocked mail is returned to the sender so a legitimate correspondent finds out, rather than vanishing silently.
Outgoing mail is monitored too, under a zero-tolerance spam policy, which is how we notice a compromised site quickly.
Backups that survive a bad day
Backups follow the 3-2-1 principle:
each server stack keeps its own redundant local copies, and a full set is written to a separate
data centre so a disaster in one place does not take your recovery option with it.
The buildings your site sits in
We partner with reputable, well-established data
centre and network providers, and we only use facilities that meet a serious physical security
standard:
Security staff on site, around the clock
Photo ID and swipe card entry, with gated access and secure perimeter fencing
CCTV coverage inside and out
Redundant and uninterruptible power
Independently accredited
The platform and facilities behind your site are
audited by third parties rather than self-certified. Staff access follows least-privilege and
need-to-know policies, centrally managed.
ISO 27001ISO 9001ISO 22301SOC 2 Type 2Cyber EssentialsThird-party hosting security accreditation
These accreditations are held by the
infrastructure and platform partners we build on. We are naming what is behind your site
rather than claiming a certificate of our own.
Being straight with you
What we cannot protect you from
A security page that only lists wins is a sales page. These are the gaps that stay
yours no matter how good the platform is, and knowing about them is most of the battle.
Still your responsibility
Your credentials. If someone gets your control panel or SFTP login, the platform will
helpfully do whatever they ask. Use a password manager and turn on multi-factor
authentication.
Your application and its plugins. We scan for malware and block a great deal at the
edge, but an out-of-date plugin with a known hole is still an open door. Update things.
What you install. A theme or plugin from an unknown source can be malicious on the
day you install it, before any scanner has seen it.
Third-party JavaScript. Anything you embed from someone else's domain runs in your
visitors' browsers with your site's privileges.
Your domain registrar. DNS is a separate account to look after, and it is worth
locking down as carefully as your hosting.
Hosting that looks after itself.
Every protection on this page is included on every plan, from the $2.99 one upwards. Nothing here is an add-on.