Every system we manage is hardened at the server level, watched continuously and patched on a defined schedule. Backups run automatically and are tested. This page explains how that works, and what access we need from you.
The same standard applies to every client, on every system
Good security is not a product you bolt on. It is a set of habits applied consistently, to every client, whether or not anyone is watching. That is how we run. Systems we host are hardened and sit behind a firewall with malware scanning running against them. Updates land on a schedule rather than when somebody remembers. Backups run automatically and are tested, so a restore is routine rather than an emergency. And because we monitor continuously, we usually know something is wrong before you do.
The standards we work to
Applied to every client, without exception.
Consistent, not selective
The same controls apply to every client on every system. Security that depends on who is asking is not security.
You stay in control
Every system stays in your ownership. You can see exactly what access we hold and withdraw it yourself, without us standing in the middle of it.
Reversible by design
A restore point exists before every change we make. If something does not go to plan, putting it back is routine rather than a rescue operation.
What we protect against
The five things we are watching for
Most incidents are not sophisticated attacks. They are ordinary maintenance that stopped happening. These are the five we see most often, and what we do about each.
01
Outdated plugins and core
The most common way a site is compromised, and the most preventable. We patch on a schedule and track vulnerability disclosures, so an exploit never gets a comfortable window.
02
Email anyone can spoof
Without SPF, DKIM and DMARC set correctly, somebody else can invoice your customers in your name. We configure all three and keep them correct as your sending changes.
03
Domains and DNS nobody owns
Registrar access left with a former contractor, renewal notices going to a dead inbox. We hold the record keeping properly, so a domain never lapses by accident.
04
Accounts that outlive people
Staff move on and their access often stays behind. Because credentials sit in a managed vault rather than in people's heads, we know what exists and what needs closing.
05
Backups nobody has tested
An untested backup is a guess. Ours run on a schedule and get tested, so recovery is something we have already rehearsed rather than something we find out about on the day.
The practices behind every engagement
Concrete, checkable, and applied the same way for every client.
Multi factor, everywhere
Every system we access and every administrative account we hold sits behind multi factor authentication. No exception is made for convenience.
Credentials in a managed vault
Held in a password manager and separated per client. No shared logins, nothing in an inbox, nothing in a spreadsheet.
Encrypted connections only
Administrative work happens over SSH, SFTP and HTTPS. Plain FTP is never used, and credentials are never sent by email.
Hardened hosting
Servers we host are hardened and sit behind a firewall, with malware scanning running against them continuously.
Patching on a schedule
Core, plugin and dependency updates happen on a defined cadence rather than when somebody remembers. That closes the window most attacks rely on.
Monitored and backed up
We watch continuously and get alerted when something changes. Backups run automatically and are tested, so recovery is rehearsed rather than improvised.
Want to see how this applies to your setup?
Tell us what you are running and we will walk you through exactly how we would secure it, and what access we would need. You will know precisely what you are agreeing to before you agree to it.