Skip to main content
.com from $2.99, and WHOIS privacy costs nothing

Security

What the platform covers, and what is left to you

The controls included on every plan, how payment data is handled, where your data lives, how to report a vulnerability — and an honest split of which risks are ours to manage and which are yours.

Included Everywhere

Security that isn't an upsell

Every control below ships on every plan, including the cheapest one. None of it is sold as an add-on.

Encryption on by default

A free SSL certificate lands on each domain without you asking, and it renews itself before the old one expires. No setup, no diary reminder, no extra line on the invoice.

Attack traffic filtered upstream

DDoS mitigation at the network level and a web application firewall screen out hostile requests before they reach your account, so a flood pointed at you never knocks the site over.

Malware scanning that runs itself

Imunify360 runs in the background looking for known malware and file changes that look wrong, which means an infected plugin gets flagged instead of sitting there unnoticed.

Backups you can actually restore

Backups run on their own every day across all plans, and higher tiers get them more often. Restore from the control panel yourself; no ticket needed.

Accounts isolated from each other

Accounts sit isolated from one another on the shared platform, so if a neighbouring site on the same server gets compromised, that stays their headache, not yours.

Card data never reaches us

Payment details go straight to Stripe, who collect and keep them. All we hold is a token plus the last four digits, so a breach on our side could not hand anyone a card number.

The Full List

What comes switched on

  • Free auto-renewing SSL on every domain
  • Network-level DDoS protection
  • Web application firewall
  • Imunify360 malware scanning
  • Automatic daily backups
  • Self-service restore from the panel
  • Account isolation on shared hosting
  • Two-factor authentication on your account
  • Brute-force login protection
  • Current PHP versions with security patches

Disclosure

Found something? Tell us.

We would much rather hear about a vulnerability from you than read about it later.

Email info@hostingally.com with as much detail as we need to reproduce it. An acknowledgement comes back, and we will keep you posted while we fix it.

Hold off on publishing until we have had a fair chance to fix it, and keep your testing away from anything that would hit other customers: no denial-of-service attempts, and no digging into data that belongs to someone else. A paid bounty is not something we run, so no reward can be promised here. Say the word, though, and we will credit you by name.

Abuse on a site we host, whether phishing, spam or malware, should go to report abuse instead. Questions about data protection are answered in our privacy policy.

Common Questions

Questions about security

Is my payment information safe?

Stripe collects your card details, and Stripe keeps them. They are one of the largest payment processors in the world, and the data sits on their infrastructure, not on ours. What comes back to us is a payment token and the last four digits: never the full number, never the security code. That is a practical point rather than a technical one. If our own systems were broken into tomorrow, there would be no card numbers sitting there for anyone to take.

Are you PCI compliant?

PCI compliance gets split between parties, so the honest answer depends on whose part you are asking about. Card data never lands on our servers at all, because Stripe handles it end to end, which puts the card-handling obligations on them; they hold PCI DSS Level 1 certification. Your own store works the same way. Run payments through a gateway such as Stripe or PayPal, where the cards are processed on the gateway's systems, and you drop into the lightest PCI category, which normally means filling in a short self-assessment questionnaire. Underneath all that we provide the encrypted, isolated, monitored infrastructure. Keeping your software current and your admin passwords strong is the bit that stays with you.

Do you hold any security certifications?

No, and we would rather put that in writing than let it stay vague. This is a small and fairly new company, and neither an ISO 27001 nor a SOC 2 audit has been done here. Both are serious pieces of work, and pretending to hold one would be a worse look than not having it. What we can show you instead: a legal identity you can verify, an upstream platform we name, the controls set out further up this page, and a disclosure route that gets answered. Where a certificate is a hard requirement on your project, we will say straight out that we are the wrong fit rather than burn your time on it.

Which datacentre holds my data, and who gets to see it?

A London datacentre holds your site files and databases. Only the staff who need it to run the platform and handle the support you have asked for can get near that access. Customer data is not for sale here, and your site content gets used for nothing beyond running the service you pay for. The legal detail lives in our privacy policy: the lawful basis for processing, retention periods, and which sub-processors are in the chain.

How do I report a vulnerability?

Send the details to info@hostingally.com and you will get an acknowledgement back. Before you go public, leave us a fair window to look into it and ship a fix. Two things we ask while you are testing: do not degrade the service for other customers, and do not go poking at data that is not yours, which rules out denial-of-service testing and any attempt to reach another account. There is no paid bounty programme running here, so a reward is not something we can promise. Credit is yours if you want it, and we will keep you posted as the fix goes in.

What is my responsibility rather than yours?

The platform is our job: server, network, firewall, malware scanning, backups, encryption. Whatever you put on top of it is yours. In practice that means WordPress, its plugins and its themes stay updated, passwords are long and used nowhere else, two-factor authentication is switched on, dead plugins get deleted rather than left lying about, and you think twice before installing somebody's code. Almost none of the compromised sites we deal with were broken into through the server. It was an out-of-date plugin, or a password recycled from somewhere else.

What happens if my site does get hacked?

Open a ticket and we will get stuck in with you. Most of the time the work runs like this: work out how they got in, roll the site back to a backup taken before the infection landed, then shut the door they came through so the whole thing does not repeat next month. That is the reason automatic daily backups count for more than any single preventative measure. Recovery is what saves you. And if the cause was a stale plugin or a weak password, expect us to say so, because silence just buys you a second incident.

Security that is not sold to you as an extra.

SSL, DDoS protection, malware scanning and daily backups on every plan — including the $2.42 one.

See Hosting Plans