Enterprise-level website security, built in.
Security breaches and malware are an ever-present threat on today’s web. Every plan includes daily malware scanning, a Web Application Firewall, anti-DDoS protection, two-factor authentication and more, all as standard, at no extra cost.
Independently certified
Not just marketing claims, real accreditations
ISO 27001
Information security management.
SOC 2 Type 2
Independently audited security controls.
Cyber Essentials
Government-backed accreditation scheme.
Malware protection
Caught early, dealt with fast
Free wildcard SSL certificates via our partnership with Let’s Encrypt cover your primary domain and every subdomain, automatically, on our own validated nameservers.
Automatic daily scanning
Every website is automatically scanned for malware every day, with on-demand scans available whenever you want one.
Detailed reports
Results appear in your control panel, including a WordPress Checksum Report for WordPress sites specifically.
Email alerts
You’re notified by email the moment malware is discovered, and PHP mail is automatically disabled on an infected site until it’s resolved.
Web Application Firewall
Instant protection, free for every customer
A two-layer defence: edge scanning before traffic even reaches your site, plus a server-level firewall for additional protection. Automatically blocks suspicious traffic, with pre-configured, highly-optimised rules for the latest threats.
Every request inspected
Our WAF inspects every HTTP request, detecting SQL injection, trojans, cross-site scripting (XSS) and path traversal, covering the OWASP top 10 attack types.
Sub-millisecond, at the edge
It runs at the very edge of our network, intercepting malicious requests before they even reach your website code, so legitimate traffic isn’t slowed down.
Rules updated regularly
Our security team keeps rules current using both commercial threat-intelligence resources and custom rules of our own.
Fully integrated, no plugins
No plugins or code changes required, and it’s 100% free for every customer, not an add-on.
Expert bot detection
Blocks unauthorised crawling, content theft and spam bots, in addition to filtering brute-force attacks and known exploits.
Helps with PCI compliance
Works alongside anti-DDoS protection, brute-force login protection, malware scanning and 2FA to help meet PCI compliance requirements.
Infrastructure
Redundant by design, isolated by role
No single point of failure. Automatic failover on hardware, software or network failure, built around a least-privilege access model and centralised identification and security policies.
Data centre security
24/7 on-site security, photo ID and swipe card entry, CCTV inside and out, gated access and secure perimeter fencing, redundant and uninterruptible power supplies.
Anti-DDoS protection
1 Tbps+ enterprise-level protection that filters malicious traffic while maintaining normal access for real visitors.
Reputation-based network blocking
IP addresses and network ranges with a bad reputation are blocked automatically, and suspicious IPs can be routed to different servers.
Isolated backups, the 3-2-1 way
Database, web, FTP and mail servers run as separate stacks, with local redundant backups plus offsite backups in a different data centre entirely.
Isolated server roles
Web servers only serve websites, MySQL servers only run MySQL, and email servers only handle email, on separate central log servers, limiting what an attacker could access even if one layer were compromised.
Autoscaling under attack
Accounts for the extra resource an attack tries to consume, so it doesn’t impact neighbouring sites on the same platform.
Email security
Spam and threats filtered before they land
Three-layer inbound scanning
Network-level checks (Spamhaus, Invaluement, Barracuda Networks), virus signature rejection, then content-based filtering, before a message ever reaches your inbox.
Fully configurable filters
Set your own allow-lists and deny-lists directly in webmail. Rejected messages are returned to sender, not silently dropped into a "black hole".
Zero-tolerance outbound spam policy
Strict controls on outgoing mail keep our sending reputation clean, protecting your own email deliverability.
Account security
Locking down access to your account
Two-factor authentication
Available for your account, Hosting Control Panel and SSH access, using TOTP apps like Google Authenticator or Microsoft Authenticator. Random security checks are also enforced for payments.
Brute-force login protection
Monitors login attempts and uses Google reCAPTCHA, blocking up to 6 million requests daily, covering WordPress and all common website logins.
IP & country blocking
Restrict access to your site or control panel by country or specific IP address, in a couple of clicks.
Self-managed tools
Extra controls, when you want them
On top of everything included by default, these are available for you to configure yourself from your control panel.
- IP address and country blocking
- Website password manager
- FTP/SFTP/Remote MySQL/SSH access control, disabled by default
- File permissions checker with auto-fix recommendations
- Automated and manual backup creation
- Secure password generator
- TLS-secured FTP/SFTP file transfers
- HTTP security headers management via the CDN
Questions
Security FAQ
Is all of this included, or is it a paid add-on?
It’s included free with every hosting plan. Malware scanning, the Web Application Firewall, anti-DDoS protection, two-factor authentication and everything else on this page is there by default, not an upsell.
Do I need to install a plugin for the Web Application Firewall?
No. It runs at the network edge, fully integrated, with nothing to install and no code changes required.
Are your data centres independently certified?
Yes. ISO 27001, SOC 2 Type 2 and Cyber Essentials accredited.
What happens if malware is found on my site?
You’re alerted by email immediately, a detailed report appears in your control panel, and PHP mail is automatically disabled on the affected site until it’s resolved.
How does two-factor authentication work?
It’s available for your account, Hosting Control Panel and SSH access, using any standard TOTP authenticator app such as Google Authenticator or Microsoft Authenticator.
Does this help with PCI compliance?
The Web Application Firewall, together with anti-DDoS protection, brute-force login protection, malware scanning and 2FA, is designed to help meet PCI compliance requirements.
What kind of support do you offer?
Real people, based in the UK, 24/7. We don’t now, and never will, use AI to handle support tickets or calls, every conversation is with a real person, every time.
Add-ons
Everything above is included. These are extra.
The protection on this page comes with every hosting plan at no cost. These four products go further, and each does something the platform deliberately does not: they work inside your website rather than around it.
Website Security
Daily scanning of your own files and database, with automatic malware removal and emergency help if you have already been hacked.
Website Backup
An independent daily copy of your site held offsite on AWS, with a longer history than the seven-day platform cycle.
Website Monitoring
Uptime, performance and certificate monitoring from 26 locations, alerting you the moment your site stops working.
SSL Certificates
Your free wildcard certificate covers encryption. These add organisation and extended validation, and a warranty behind them.
24/7 UK-based support, no AI
Real people, based in the UK, every time you get in touch.
No upsells on essential features
All customers get the same pricing and treatment, regardless of size.
100% renewable hosting, verified
Every server we host runs on renewable energy, verified by the Green Web Foundation.