How we secure your website and data

Security is a chain: the network, the server, the connection, your website and your own account. The first three links are ours: we keep attacks off the network, maintain the server and encrypt the connection. The last two are yours: keeping your CMS and plugins up to date, and making sure nobody gets in with your password.

One weak link makes the rest worthless. A perfectly patched server does not help if a three-year-old plugin is running on your site. Below you can read, link by link, what happens and who does it.

What we do

  • Stop DDoS traffic at network level, before it reaches your site
  • Update the operating system, the web server and the PHP versions
  • Isolate sites on the same server from one another
  • Install a free SSL certificate and renew it automatically
  • Back up files and database daily, kept for 14 days

What you do

  • Keep your CMS, theme and plugins up to date
  • Use strong, unique passwords and enable two-factor authentication
  • Give users no more rights than they need
  • Delete plugins you do not use, rather than just deactivating them
  • Let us know when you see something unusual
Link 1 · the network

At network level: DDoS protection

In a DDoS attack, thousands of devices send traffic to your site at the same time with the sole aim of overloading it. Nothing is stolen; your site is simply unreachable. At WWW4 that traffic is recognised and stopped on our network infrastructure before it reaches your site. That comes with every plan, without you having to configure anything.

To be fair: DDoS protection keeps your site reachable during an overload attack, nothing more. It does not stop an intruder who gets in through an outdated plugin or a weak password. That is what the other links are for.

About DDoS protection
Link 2 · the server

On the server: maintenance and isolation

A website runs on an operating system, a web server and a PHP version. Those three are ours, and they are exactly where most vulnerabilities arise when nobody maintains them.

We keep the server side up to date

The operating system, the web server and the PHP versions we offer are updated by us. You do not need to do anything for that and normally will not notice it. What runs on top, your CMS and plugins, is your side of the chain.

Sites are isolated from one another

On shared hosting, several sites live on one server. Each site runs in its own isolated space, with its own files and its own databases. A problem at another customer gives no access to your site.

You choose your own PHP version

Per site and at any time. A recent PHP version receives security updates; an old one no longer does. So put your site on the newest version your theme and plugins support, and switch back if an update disappoints.

Which PHP version to choose? Need your own server?
Link 3 · the connection

In transit: encrypted via SSL

Everything that travels between your visitor and your site — passwords, forms, orders — goes encrypted over https. Every hosting plan includes a free Let's Encrypt certificate that is renewed automatically. So there is no expiry date for you to watch.

If you want visitors to see in the certificate which company is behind the site, you can choose a paid certificate with organisation validation. For the encryption itself it makes no difference.

About SSL certificates
Link 4 · when things go wrong

When things do go wrong

No security is complete. That is why what is ready for the moment things go wrong matters: a failed update, a human error or a hacked site.

Daily backup, 14 days

A backup of your files and your database is made every day and kept for 14 days. That is included; you do not need to set anything up.

Restore on request

Contact support with your domain name and the time when everything still worked. The more precisely you know that, the more targeted the restore can be. Do not keep working on the site in the meantime.

Monitoring and status page

We monitor our infrastructure and servers. If there is an outage or planned maintenance, you will see it on the status page, so you do not have to guess whether the problem is your site or us.

About backup & restore Service status Recover a hacked website
Link 5 · your website and your account

What you do yourself

Most incidents we see do not start at the server but in the website itself: a plugin that has not been updated for months, or a password that was also used elsewhere. These are the habits that make the difference.

Keep your CMS, theme and plugins up to date. Outdated plugins are the most common cause of a hacked site.
Use strong, unique passwords for your CMS, your control panel and your mailboxes, and store them in a password manager.
Enable two-factor authentication wherever you can. A leaked password alone is then no longer enough.
Give users no more rights than necessary. Someone who only writes articles does not need to be an administrator. Remove the accounts of people who have left.
Clean up your plugins. Delete what you do not use. A deactivated plugin is still on the server and can still contain a vulnerability.
Make an extra backup before a major change, such as a CMS upgrade or a new theme. Our daily backup is a safety net, not a substitute for caution.
Securing WordPress Updating WordPress safely

Further reading

Where your data physically sits, what that means for the GDPR, and what we commit to regarding availability.

Data location and GDPR Our data centers Our SLA

Frequently asked questions about security

No, and no honest hosting provider says so. We secure the network, the server and the connection, and make sure a daily backup is ready when things go wrong. But your website itself, with its CMS, theme, plugins and user accounts, remains the link where most incidents begin. Security only works when both sides do their part.
We stop DDoS traffic at network level, update the operating system, the web server and the PHP versions, isolate sites on the same server from one another, install a free SSL certificate and make a daily backup. You keep your CMS, theme and plugins up to date, use strong passwords with two-factor authentication, and give users no more rights than necessary.
No. DDoS protection keeps your site reachable when someone tries to overload it with traffic. It does not stop an intruder who gets in through an outdated plugin, a weak password or a flaw in your application. For that, the maintenance of your website and good passwords are decisive.
No. Every hosting plan includes a free Let's Encrypt certificate that is renewed automatically, so your site is reachable over https without you having to watch an expiry date. A paid certificate is only needed if you want organisation validation: then the name of your company appears in the certificate. For the encryption itself it makes no difference.
Contact support with your domain name and the moment when the site was still in order. Restoring to a clean backup is usually faster and safer than cleaning up. After that the cause has to go, otherwise the intruder comes back: usually that is an outdated plugin or a leaked password. After a hack, change all passwords of your CMS, control panel and mailboxes.
Fourteen days. A backup of your files and your database is made daily, and it is included with every hosting plan. You request a restore from support. Make an extra backup yourself before a major change such as a CMS upgrade, and also keep a copy of your most important files yourself.
No. On shared hosting several sites live on one server, but each site runs in its own isolated space with its own files and its own databases. A hacked site of another customer gives no access to yours. If you want a completely separate environment, a managed VPS is the next step.
In two Belgian data centers, in Brussels and Ghent, on servers we manage ourselves. Your data does not leave Belgium. If you want to set out how we handle personal data as a processor, you receive a data processing agreement on request, even before you become a customer.
Call us
Send an email