Skip to main content
Claim your .com from $2.99 — free WHOIS privacy included

Security

What protects your site, and what's on you

The controls included on every plan, how payment data is handled, where your data lives, how to report a vulnerability — and an honest split of which risks are ours to manage and which are yours.

Included Everywhere

Security that isn't an upsell

Every control below ships on every plan, including the cheapest one. None of it is sold as an add-on.

Encryption on by default

A free SSL certificate is issued automatically for every domain and renews itself before it can lapse. Nothing to configure, nothing to remember, no separate charge.

Attack traffic filtered upstream

Network-level DDoS mitigation and a web application firewall screen malicious requests before they reach your account, so a flood aimed at you doesn't take your site down.

Malware scanning that runs itself

Imunify360 watches for known malware and suspicious file changes in the background, so an infected plugin is caught rather than quietly left in place.

Backups you can actually restore

Automatic daily backups on every plan, more frequently on higher tiers, restorable yourself from the control panel without opening a ticket.

Accounts isolated from each other

Every account runs isolated on the shared platform, so another site on the same server being compromised does not become your problem.

Card data never reaches us

Stripe collects and stores payment details directly. We hold a token and the last four digits, so a breach of our systems could not expose a card number.

The Full List

What comes switched on

  • Free auto-renewing SSL on every domain
  • Network-level DDoS protection
  • Web application firewall
  • Imunify360 malware scanning
  • Automatic daily backups
  • Self-service restore from the panel
  • Account isolation on shared hosting
  • Two-factor authentication on your account
  • Brute-force login protection
  • Current PHP versions with security patches

Disclosure

Found something? Tell us.

We would much rather hear about a vulnerability from you than read about it later.

Email info@hostingally.com with enough detail to reproduce the issue. We will acknowledge your report and keep you posted on the fix.

Please give us a reasonable window to resolve it before going public, and please do not test in ways that affect other customers — no denial-of-service testing and no attempts to reach data that is not yours. We do not operate a paid bounty, so we cannot promise a reward, but we will credit you if you would like.

Abuse on a site we host — phishing, spam, malware — goes to report abuse instead. Data protection questions are covered in our privacy policy.

Common Questions

Questions about security

Is my payment information safe?

Your card details are collected by Stripe, one of the largest payment processors in the world, and are stored on their infrastructure rather than ours. We receive a payment token and the last four digits — never the full card number, and never the security code. This matters practically as well as technically: even in the worst case where our own systems were compromised, there would be no card numbers there to steal.

Are you PCI compliant?

PCI compliance is a shared responsibility, and the honest answer depends on which part you mean. Because card data is handled entirely by Stripe and never touches our servers, the card-handling obligations sit with them, and they are PCI DSS Level 1 certified. For your own store, the same logic applies: if you use a gateway like Stripe or PayPal that processes cards on its own systems, you fall into the lightest PCI category, usually a short self-assessment questionnaire. We supply the encrypted, isolated, monitored infrastructure underneath; you keep your software current and your admin passwords strong.

Do you hold any security certifications?

Not currently, and we would rather say so than imply otherwise. We are a small, newer company and we have not been through ISO 27001 or SOC 2 audits — those are substantial undertakings and claiming them falsely would be worse than lacking them. What we can point to is a verifiable legal identity, a named upstream platform, the specific controls listed on this page, and a disclosure route that works. If a certification is a hard requirement for your project, we will tell you plainly that we are not the right fit rather than waste your time.

Where is my data stored, and who can access it?

Your site files and databases are stored in a London datacentre. Access is limited to the staff who need it to operate the platform and provide the support you ask for. We do not sell customer data, and we do not use your site content for anything other than running the service. Our privacy policy sets out the legal detail, including the basis for processing, how long we keep things, and the sub-processors involved.

How do I report a vulnerability?

Email info@hostingally.com with the detail and we will acknowledge it. Please give us a reasonable window to investigate and fix before disclosing publicly, and please do not test in a way that degrades service for other customers or accesses data that is not yours — no denial-of-service testing, no attempts to reach other accounts. We do not run a paid bounty programme, so we cannot promise a reward, but we will credit you if you would like us to and we will keep you updated on the fix.

What is my responsibility rather than yours?

We secure the platform: the server, the network, the firewall, the malware scanning, the backups and the encryption. You secure what you put on it. That means keeping WordPress and its plugins and themes updated, using strong and unique passwords with two-factor authentication enabled, removing plugins you no longer use, and being careful about what code you install. The overwhelming majority of compromised sites we see are not breached through the server — they are breached through an outdated plugin or a reused password.

What happens if my site does get hacked?

Open a ticket and we will help. In practice that usually means identifying how the compromise happened, restoring from a clean backup taken before the infection, and making sure the entry point is closed so it does not simply recur. This is why the automatic daily backups matter more than any single preventative control — recovery is what actually saves you. If the cause was an outdated plugin or a weak password, we will tell you that too, because otherwise it happens again.

Security you don't have to buy separately.

SSL, DDoS protection, malware scanning and daily backups on every plan — including the $2.09 one.

See Hosting Plans