aoitcloud
Included, free ISO 27001 & SOC2 Type 2

Enterprise-level website security, built in.

Security breaches and malware are an ever-present threat on today’s web. Every plan includes daily malware scanning, a Web Application Firewall, anti-DDoS protection, two-factor authentication and more, all as standard, at no extra cost.

ISO 27001 data centres PCI compliant Climate-positive hosting UK data centres

Independently certified

Not just marketing claims, real accreditations

ISO 27001

Information security management.

SOC 2 Type 2

Independently audited security controls.

Cyber Essentials

Government-backed accreditation scheme.

Malware protection

Caught early, dealt with fast

Free wildcard SSL certificates via our partnership with Let’s Encrypt cover your primary domain and every subdomain, automatically, on our own validated nameservers.

Automatic daily scanning

Every website is automatically scanned for malware every day, with on-demand scans available whenever you want one.

Detailed reports

Results appear in your control panel, including a WordPress Checksum Report for WordPress sites specifically.

Email alerts

You’re notified by email the moment malware is discovered, and PHP mail is automatically disabled on an infected site until it’s resolved.

Web Application Firewall

Instant protection, free for every customer

A two-layer defence: edge scanning before traffic even reaches your site, plus a server-level firewall for additional protection. Automatically blocks suspicious traffic, with pre-configured, highly-optimised rules for the latest threats.

Every request inspected

Our WAF inspects every HTTP request, detecting SQL injection, trojans, cross-site scripting (XSS) and path traversal, covering the OWASP top 10 attack types.

Sub-millisecond, at the edge

It runs at the very edge of our network, intercepting malicious requests before they even reach your website code, so legitimate traffic isn’t slowed down.

Rules updated regularly

Our security team keeps rules current using both commercial threat-intelligence resources and custom rules of our own.

Fully integrated, no plugins

No plugins or code changes required, and it’s 100% free for every customer, not an add-on.

Expert bot detection

Blocks unauthorised crawling, content theft and spam bots, in addition to filtering brute-force attacks and known exploits.

Helps with PCI compliance

Works alongside anti-DDoS protection, brute-force login protection, malware scanning and 2FA to help meet PCI compliance requirements.

Infrastructure

Redundant by design, isolated by role

No single point of failure. Automatic failover on hardware, software or network failure, built around a least-privilege access model and centralised identification and security policies.

Data centre security

24/7 on-site security, photo ID and swipe card entry, CCTV inside and out, gated access and secure perimeter fencing, redundant and uninterruptible power supplies.

Anti-DDoS protection

1 Tbps+ enterprise-level protection that filters malicious traffic while maintaining normal access for real visitors.

Reputation-based network blocking

IP addresses and network ranges with a bad reputation are blocked automatically, and suspicious IPs can be routed to different servers.

Isolated backups, the 3-2-1 way

Database, web, FTP and mail servers run as separate stacks, with local redundant backups plus offsite backups in a different data centre entirely.

Isolated server roles

Web servers only serve websites, MySQL servers only run MySQL, and email servers only handle email, on separate central log servers, limiting what an attacker could access even if one layer were compromised.

Autoscaling under attack

Accounts for the extra resource an attack tries to consume, so it doesn’t impact neighbouring sites on the same platform.

Email security

Spam and threats filtered before they land

Three-layer inbound scanning

Network-level checks (Spamhaus, Invaluement, Barracuda Networks), virus signature rejection, then content-based filtering, before a message ever reaches your inbox.

Fully configurable filters

Set your own allow-lists and deny-lists directly in webmail. Rejected messages are returned to sender, not silently dropped into a "black hole".

Zero-tolerance outbound spam policy

Strict controls on outgoing mail keep our sending reputation clean, protecting your own email deliverability.

Account security

Locking down access to your account

Two-factor authentication

Available for your account, Hosting Control Panel and SSH access, using TOTP apps like Google Authenticator or Microsoft Authenticator. Random security checks are also enforced for payments.

Brute-force login protection

Monitors login attempts and uses Google reCAPTCHA, blocking up to 6 million requests daily, covering WordPress and all common website logins.

IP & country blocking

Restrict access to your site or control panel by country or specific IP address, in a couple of clicks.

Self-managed tools

Extra controls, when you want them

On top of everything included by default, these are available for you to configure yourself from your control panel.

  • IP address and country blocking
  • Website password manager
  • FTP/SFTP/Remote MySQL/SSH access control, disabled by default
  • File permissions checker with auto-fix recommendations
  • Automated and manual backup creation
  • Secure password generator
  • TLS-secured FTP/SFTP file transfers
  • HTTP security headers management via the CDN

Questions

Security FAQ

Is all of this included, or is it a paid add-on?

It’s included free with every hosting plan. Malware scanning, the Web Application Firewall, anti-DDoS protection, two-factor authentication and everything else on this page is there by default, not an upsell.

Do I need to install a plugin for the Web Application Firewall?

No. It runs at the network edge, fully integrated, with nothing to install and no code changes required.

Are your data centres independently certified?

Yes. ISO 27001, SOC 2 Type 2 and Cyber Essentials accredited.

What happens if malware is found on my site?

You’re alerted by email immediately, a detailed report appears in your control panel, and PHP mail is automatically disabled on the affected site until it’s resolved.

How does two-factor authentication work?

It’s available for your account, Hosting Control Panel and SSH access, using any standard TOTP authenticator app such as Google Authenticator or Microsoft Authenticator.

Does this help with PCI compliance?

The Web Application Firewall, together with anti-DDoS protection, brute-force login protection, malware scanning and 2FA, is designed to help meet PCI compliance requirements.

What kind of support do you offer?

Real people, based in the UK, 24/7. We don’t now, and never will, use AI to handle support tickets or calls, every conversation is with a real person, every time.

24/7 UK-based support, no AI

Real people, based in the UK, every time you get in touch.

No upsells on essential features

All customers get the same pricing and treatment, regardless of size.

100% renewable hosting, verified

Every server we host runs on renewable energy, verified by the Green Web Foundation.

Get in touch

Drop our team a message today