How we protect our platform
| Area | What we do |
|---|---|
| Network | Hardware firewalls and hardware DDoS protection in front of our infrastructure, plus server firewalls |
| Threat alerts | Our network and infrastructure are registered with the National Cyber Security Centre’s Early Warning service, so we’re alerted to threats and vulnerabilities affecting our systems |
| Websites | A web application firewall and malware scanning (cPFence) |
| Account isolation | Each hosting account runs isolated from the others (CloudLinux / Enhance containerisation) |
| Patching | Operating systems, control panels and server software kept up to date, with security patches applied promptly |
| Encryption | TLS on the control panel, client area, email and websites, with free SSL certificates |
| Outgoing email is filtered for spam and malware (MailChannels) | |
| Backups | Regular off-server backups, kept for 30 days in the UK and EEA |
| Staff access | Least-privilege access, with multi-factor authentication on admin systems |
| Payments | Handled by PCI DSS-compliant providers, so we never store full card details |
If something does go wrong
We have a documented process for investigating security incidents. If a personal data breach affects data you store with us, we’ll notify you without undue delay, and in any case within 48 hours.
What you can do
Security works best as a partnership. The biggest things you can do are:
- Turn on two-factor authentication on your client account and your Enhance control panel.
- Use strong, unique passwords for everything.
- Keep your website software up to date, including WordPress, plugins and themes.
- Keep your own backups of anything important.