
There is no separate security product to remember to buy, because a site we are responsible for never ships without protection. The security layer is our own plugin: fourteen hardening controls, login lockout, security headers and a daily vulnerability scan delivering its own updates over a cryptographically signed channel.
| Hardening | Applied at setup and maintained |
|---|---|
| Patching | In a maintenance window, not at random |
| Scanning | A daily vulnerability scan that fails honestly: if it cannot check, it says so instead of showing green |
| SSL | Configured and kept renewed |
| Backups | Nightly, written to storage separate from the server |
| Recovery | A bad update is a restore, not a rebuild |
| Included from | All plans |
A backup stored on the same server it protects is not a backup Backups Kept Elsewhere If the machine goes, the copy goes with it. Yours are written nightly to separate storage, so a bad update, a broken plugin or a compromised site is a restore measured in minutes rather than a rebuild measured in days. Infrastructure → . Across our entire infrastructure - the engines that publish, route, and monitor for you -backups run nightly and are encrypted before leaving the machine. Retained for 30 days, their decryption keys are kept strictly offline. Ours are written somewhere separate, every night, so the recovery starts from a known good state.
Monitoring alerts us, and in most cases we are working on it before anyone tells us. If a bad update caused it, the nightly backup means a rollback rather than a debugging session.
Nightly, with a rolling window. If you need a longer retention period for a compliance reason, tell us and we will scope it.
No, and nobody honestly can. What we control is how hard it is to get in, how fast we notice, and what state the recovery starts from.
Most people have never tried. We will tell you what yours would look like.