Everything above is our side of the line
The server, the operating system, the security software, the network, the backups
Security
Protection starts the day your site goes live, and isolation keeps other accounts away from your files.
Malware scanning on every plan WAF & DDoS mitigation Daily off-site backups Free auto-renewing SSL
Blue Arctic runs two hosting platforms, and they do not run the same software.
Imunify360 scans every file write and locks infected files away, so an infection is contained rather than left to spread.
SQL injection, cross-site scripting, path traversal and brute-force login attempts. Its rule sets update continuously.
CloudLinux LVE containers give every account its own CPU, memory and process limits, enforced at the kernel level, the core of the operating system. CageFS keeps each account’s files out of view of the others. Activity in another account is contained rather than becoming your problem.
A different platform with a different job, so it runs a different set of tools. Patchstack vulnerability protection, RapidMitigate virtual patching, a web application firewall, real-time malware scanning, and two-factor protection on WordPress logins. It reduces your exposure to known vulnerabilities. No security tool can make any website immune to every attack.
Visitors get the padlock in their browser and a private connection to your site. We issue and renew the certificate on every domain automatically. TLS 1.3 with TLS 1.2 fallback, and deprecated protocols disabled.
We back up hosting accounts daily to separate infrastructure and keep 30 days of them, under our Terms of Service. On VPS the window is 5 days, held as 5 recovery points. Our engineers handle restores: open a ticket, and we will confirm the recovery point with you first. Backups are a safety net, not a certainty. Keep your own copies of anything business-critical.
When someone floods your site with fake traffic to knock it offline, we filter that traffic at the network edge, before it reaches the server your site runs on. Very large attacks can still cause a brief interruption while mitigation engages.
Our hardware lives in a Tampa, FL datacenter, behind 24/7 monitored access control and camera coverage. The detail is on the infrastructure page.
Already hacked, on any host? Emergency Malware Removal is $199 flat per incident. Our written guarantee: If we do not successfully remove the malware and secure the identified entry point, we refund the engagement in full. Clients who move to a monthly plan afterward receive the first month at no charge. Request emergency removal. Hardening your own server instead is Server Administration.
One thing to know up front. If a site hosted here is actively distributing malware, we may suspend it while we clean it up. Better you read that now than learn it mid-incident.
The server, the operating system, the security software, the network, the backups
What none of that does is make a website immune to compromise
Where we tell you a security patch, update or configuration change is needed and it is not applied, SLA Section 5 excludes service credits for problems that follow. Read the SLA.
Standard plans are not HIPAA, PCI DSS, SOC 2, CJIS, or CMMC compliant environments. If your framework needs more than strong operational security, we build that as a custom engagement, scoped and quoted individually.
No. Everything above is the default configuration on the cheapest plan and on the most expensive one, on both platforms.
Infected files are quarantined automatically, and our engineers review flagged events rather than leaving them in a dashboard. We clean up what is confirmed and trace how it got in. A site actively distributing malware may be suspended while that work happens. If your site is hosted elsewhere and has already been hacked, Emergency Malware Removal is $199 flat, with no hosting plan required.
No. The standard security software is strong operational security, not a compliance environment. The compliance section further down this page lists the frameworks we build compliance engagements for, and how one is scoped.
Every plan ships with it. If your site is already in trouble, there is a fixed-price fix.