Security
Provide for the common defense.
Security isn’t an add-on we sell you at checkout. It’s built into every layer of the platform, and it’s on for every site, on every plan.
Defense in depth
Six layers between attackers and your site.
At the edge
TLS 1.3 everywhere, a web application firewall running the OWASP Core Rule Set, login rate limits and protection against slow-client attacks, before traffic ever reaches your site.
Across the network
When an address hammers logins on one server, it is blocked on every server. Blocks escalate for repeat offenders and are enforced in the kernel firewall.
Around every site
Each site is its own Linux user inside a systemd sandbox with a private filesystem view and hard cgroup limits. Sites can’t read each other’s files, even on the same account.
Inside your code
Incremental malware scans with plain-English findings, WordPress checksum verification, quarantine and one-click restore of anything flagged by mistake.
Around your data
Databases are never exposed to the public internet. Developers connect through encrypted SSH tunnels, and backups are encrypted.
At your front door
Two-factor authentication, passkeys, recovery codes, per-person SSH keys, session management and a full audit log of every change and sign-in.
No bad neighbors
Why isolation matters.
On traditional shared hosting, hundreds of sites often run as users on one big server with loose boundaries. When one gets hacked, attackers go looking for the next. That’s how a stranger’s outdated plugin becomes your problem.
We isolate every single site: its own user, its own PHP processes, its own cache, its own CPU and memory ceilings, enforced by the Linux kernel. Even two sites on the same account are walled off from each other.
Our commitments
Privacy, the American way.
- Your files, databases and backups are stored in U.S. data centers.
- We never sell your data or your visitors’ data. Period.
- Card details are handled by Stripe and never touch our servers.
- Staff access to your account is limited, and every staff action is logged.
- Security updates for our servers are applied automatically.
Report a security issue
Found a vulnerability in our platform or a site abusing our network? Tell us. We investigate every report.
Security questions
Questions, answered.
How do you keep my site secure?
Every site runs as its own locked-down user inside its own sandbox with hard resource limits, so a hacked site next door can’t reach yours. On top of that: a web application firewall (OWASP Core Rule Set) in front of every site, automatic IP blocking of brute-force attacks across our whole network, malware scanning with one-click quarantine, WordPress core integrity checks, free SSL on every domain and two-factor login with passkeys for your account.
Do you back up my site?
Every day, on every plan, at no extra charge. Backups are kept for 7 days on Minuteman, 14 on Main Street, 30 on Frontier and 60 on Liberty. You can restore a whole site, just the files or just a database yourself from the control panel.
Do I get SSL certificates?
Yes, free and automatic for every domain and subdomain you add, renewed without you lifting a finger. There is nothing to buy and nothing to install.
Can I use SSH and SFTP?
SFTP with SSH keys is included on every plan. Main Street and above add a full SSH shell, a browser-based terminal and secure database tunnels, so you can connect tools like TablePlus or MySQL Workbench without exposing your database to the internet.
Put your site under guard.
Honest prices that never jump at renewal, U.S. servers, and real people who pick up the thread. Try us for 30 days, risk-free.