Security
What we lock, and what you lock
The controls that ship on every plan, how payment data is handled, where your files sit, how to report a flaw — and a straight split of which risks are ours to carry and which are yours.
Included Everywhere
Security isn't sold separately here
Every control below is on every plan, the cheapest one included. None of it carries an add-on price tag.
HTTPS switched on for you
Every domain gets a free SSL certificate issued automatically, and it renews itself before it can expire. Nothing to set up, nothing to diarise, nothing extra to pay.
Bad traffic stopped upstream
DDoS mitigation at the network level and a web application firewall sift out hostile requests before they reach your account, so a flood aimed at you doesn't knock the site over.
Malware scanning, unattended
Imunify360 keeps watch in the background for known malware and odd file changes, so a poisoned plugin gets found instead of sitting there quietly.
Backups you can put back yourself
Daily automatic backups on every plan, more often on the higher tiers, restored from the control panel without waiting on a ticket.
Each account walled off
Accounts run isolated from one another on the shared platform, so another site on the same server being compromised doesn't become your problem.
We never see your card
Stripe takes and keeps the payment details. All we hold is a token and the last four digits, so there is no card number here for anyone to steal.
The Full List
What's switched on already
- Free SSL on every domain, self-renewing
- DDoS filtering at the network level
- A web application firewall in front
- Imunify360 scanning for malware
- Backups taken automatically every day
- Restore them yourself from the panel
- Accounts isolated on shared hosting
- Two-factor sign-in on your account
- Brute-force protection on logins
- Up-to-date PHP with security patches applied
Disclosure
Found a hole? Tell us.
We would far rather hear about a vulnerability from you than read about it somewhere else.
Email info@hosting-seller.com with enough detail for us to reproduce the issue. We will acknowledge your report and keep you updated as the fix goes in.
Please give us a fair window to sort it out before going public, and please do not test in ways that touch other customers — no denial-of-service testing, and no attempts to reach data that is not yours. There is no paid bounty here, so we cannot promise a reward, but we will credit you if you want it.
Abuse on a site we host — phishing, spam, malware — belongs at report abuse instead. Data protection questions are answered in our privacy policy.
Common Questions
Questions about security
Is my card safe with you?
Your card details go to Stripe, one of the largest payment processors there is, and live on their systems rather than ours. What we receive is a payment token and the last four digits — never the full number, and never the security code. That is a practical point as much as a technical one: if our own systems were broken into tomorrow, there would be no card numbers sitting there to take.
Where do you stand on PCI compliance?
PCI is a shared responsibility, so the honest answer depends which part you are asking about. Card data is handled entirely by Stripe and never touches our servers, which puts the card-handling obligations with them — and they hold PCI DSS Level 1 certification. The same reasoning applies to your own shop: run payments through a gateway like Stripe or PayPal that processes cards on its own systems and you land in the lightest PCI category, usually a short self-assessment questionnaire. We supply the encrypted, isolated, monitored platform underneath. You keep your software current and your admin passwords strong.
Do you have any security certifications?
No, and we would rather say so than imply otherwise. We are a small, young company and we have not been through ISO 27001 or SOC 2 — those are serious undertakings, and claiming them falsely would be worse than not holding them. What we can point at is a verifiable legal identity, a named upstream platform, the specific controls listed on this page, and a disclosure route that works. If a certificate is a hard requirement on your side, we will tell you plainly that we are not the right shop rather than waste your time.
Where do my files live, and who can reach them?
Your site files and databases sit in a London datacentre. Access is restricted to the staff who need it to run the platform and answer the support you ask for. We do not sell customer data, and we do not use your site content for anything except operating the service. Our privacy policy carries the legal detail — the lawful basis for processing, how long things are kept, and the sub-processors involved.
How do I report a security flaw?
Email info@hosting-seller.com with the details and we will acknowledge it. Please leave us a reasonable window to investigate and fix before you go public, and please do not test in ways that degrade the service for other customers or reach data that is not yours — no denial-of-service testing, no poking at other accounts. There is no paid bounty here, so we cannot promise a reward, but we will credit you if you would like and we will keep you updated as the fix lands.
Which bits are mine to look after?
We secure the platform: the server, the network, the firewall, the malware scanning, the backups and the encryption. You secure what you put on it. In practice that means keeping WordPress and its plugins and themes updated, using strong unique passwords with two-factor turned on, deleting plugins you have stopped using, and thinking twice about what code you install. Almost every compromised site we see was not broken into through the server — it was an out-of-date plugin or a reused password.
What if my site gets hacked anyway?
Open a ticket and we will help. That usually means working out how they got in, restoring from a clean backup taken before the infection, and closing the entry point so it does not simply happen again. This is why the daily automatic backups matter more than any single preventative measure — recovery is the part that actually saves you. If the cause was a stale plugin or a weak password, we will say so, because otherwise you will be back here in a month.
Security that's already on the ticket.
SSL, DDoS filtering, malware scanning and daily backups on every plan — the $2.09 one included.
Browse Hosting Plans