Skip to main content
HostingSeller
Shop plans

Security

The locks we hold, the locks you hold

The controls that ship on every plan, how payment data is handled, where your files sit, how to report a flaw — and a straight split of which risks are ours to carry and which are yours.

Included Everywhere

Security isn't sold separately here

Every control below is on every plan, the cheapest one included. None of it carries an add-on price tag.

HTTPS switched on for you

A free SSL certificate is issued to every domain without you asking, and it renews itself ahead of expiry. Nothing to configure. Nothing to write in the diary. Nothing extra on the bill.

Bad traffic stopped upstream

Hostile requests are sifted out by DDoS mitigation working at network level and by a web application firewall in front of your account, which is why a flood pointed at your site does not put it on the floor.

Malware scanning, unattended

Working away in the background, Imunify360 looks for known malware and for file changes that make no sense, which is how a poisoned plugin gets caught rather than left alone.

Backups you can put back yourself

Backups run daily on every plan, more often as you go up the tiers, and you restore them from the control panel rather than queueing behind a ticket.

Each account walled off

On the shared platform each account runs walled off from its neighbours, so a site on the same server getting compromised never turns into your problem.

We never see your card

Payment details are taken and kept by Stripe. On our side there is a token and the last four digits, which means no card number sits here waiting for a thief to find it.

The Full List

What's switched on already

  • Free SSL on every domain, self-renewing
  • DDoS filtering at the network level
  • A web application firewall in front
  • Imunify360 scanning for malware
  • Backups taken automatically every day
  • Restore them yourself from the panel
  • Accounts isolated on shared hosting
  • Two-factor sign-in on your account
  • Brute-force protection on logins
  • Up-to-date PHP with security patches applied

Disclosure

Found a hole? Tell us.

We would far rather hear about a vulnerability from you than read about it somewhere else.

Email info@hosting-seller.com with enough detail that we can reproduce the issue at our end. Your report gets acknowledged, and we will keep you posted while the fix goes in.

Give us a fair window to put it right before you go public, and keep your testing away from other customers. That rules out denial-of-service testing, and any attempt to reach data belonging to someone else. No paid bounty runs here, so a reward is not something we can promise. Credit, though, is yours for the asking.

Abuse on a site we host, whether phishing, spam or malware, belongs at report abuse instead. Questions about data protection get answered inside our privacy policy.

Common Questions

Questions about security

Is my card safe with you?

Card details travel to Stripe, one of the largest payment processors in existence, and they live on Stripe's systems instead of ours. All that comes back to us is a payment token and the last four digits. Never the full number. Never the security code. The point is as practical as it is technical: were our own systems broken into tomorrow morning, a thief would find no card numbers here to carry off.

Where do you stand on PCI compliance?

PCI splits the responsibility, so the honest answer depends on which piece you mean. Card data is handled from end to end by Stripe and never lands on our servers, which parks the card-handling obligations with them, and Stripe holds PCI DSS Level 1 certification. Your own shop works the same way. Run payments through a gateway such as Stripe or PayPal, one that processes cards on its own systems, and you drop into the lightest PCI category, which normally means a short self-assessment questionnaire. Underneath all that we supply the encrypted, isolated, monitored platform. Keeping your software current and your admin passwords strong is the half that belongs to you.

Do you have any security certifications?

No, and saying so beats hinting otherwise. This is a small, young company that has not been through ISO 27001 or SOC 2. Both are serious undertakings, and claiming one falsely would be worse than simply not holding it. What we can point you at is a legal identity you can verify, an upstream platform we name, the specific controls set out on this page, and a disclosure route that actually works. Where a certificate is a hard requirement at your end, we will say plainly that this is the wrong shop for you rather than eat up your time.

Where do my files sit, and who has access to them?

A London datacentre holds your site files and databases. Reaching them is limited to the staff who need that access to run the platform and to answer the support questions you send in. Customer data is not for sale here, and your site content gets used for one thing only: running the service you bought. The legal detail sits in our privacy policy, which sets out the lawful basis for processing, how long anything is kept, and which sub-processors are involved.

How do I report a security flaw?

Email info@hosting-seller.com with the details and we will acknowledge it. Please leave us a reasonable window to investigate and fix before you go public, and please do not test in ways that degrade the service for other customers or reach data that is not yours — no denial-of-service testing, no poking at other accounts. There is no paid bounty here, so we cannot promise a reward, but we will credit you if you would like and we will keep you updated as the fix lands.

Which bits are mine to look after?

The platform is ours to secure: server, network, firewall, malware scanning, backups, encryption. Whatever you put on top of it is yours. In practice that means WordPress, its plugins and its themes stay updated, passwords are strong and used nowhere else, two-factor is switched on, plugins you have stopped using get deleted, and you think twice before installing somebody's code. Nearly every compromised site we come across was not broken into through the server. It was a stale plugin, or a password reused from somewhere else.

What if my site gets hacked anyway?

Open a ticket and we get involved. Usually that means working out how they got in, rolling the site back to a clean backup taken before the infection, and shutting the door they came through so the whole thing does not repeat. It is the reason a daily automatic backup counts for more than any single preventative measure: recovery is what actually saves you. Should the cause turn out to be a stale plugin or a weak password, we will tell you, because otherwise you are back here inside a month.

Security already priced into the ticket.

SSL, DDoS filtering, malware scanning and daily backups on every plan — the $2.42 one included.

Browse Hosting Plans