How we secure your website and data
Security is a chain: the network, the server, the connection, your website and your own account. The first three links are ours: we keep attacks off the network, maintain the server and encrypt the connection. The last two are yours: keeping your CMS and plugins up to date, and making sure nobody gets in with your password.
One weak link makes the rest worthless. A perfectly patched server does not help if a three-year-old plugin is running on your site. Below you can read, link by link, what happens and who does it.
What we do
- Stop DDoS traffic at network level, before it reaches your site
- Update the operating system, the web server and the PHP versions
- Isolate sites on the same server from one another
- Install a free SSL certificate and renew it automatically
- Back up files and database daily, kept for 14 days
What you do
- Keep your CMS, theme and plugins up to date
- Use strong, unique passwords and enable two-factor authentication
- Give users no more rights than they need
- Delete plugins you do not use, rather than just deactivating them
- Let us know when you see something unusual
At network level: DDoS protection
In a DDoS attack, thousands of devices send traffic to your site at the same time with the sole aim of overloading it. Nothing is stolen; your site is simply unreachable. At WWW4 that traffic is recognised and stopped on our network infrastructure before it reaches your site. That comes with every plan, without you having to configure anything.
To be fair: DDoS protection keeps your site reachable during an overload attack, nothing more. It does not stop an intruder who gets in through an outdated plugin or a weak password. That is what the other links are for.
On the server: maintenance and isolation
A website runs on an operating system, a web server and a PHP version. Those three are ours, and they are exactly where most vulnerabilities arise when nobody maintains them.
We keep the server side up to date
The operating system, the web server and the PHP versions we offer are updated by us. You do not need to do anything for that and normally will not notice it. What runs on top, your CMS and plugins, is your side of the chain.
Sites are isolated from one another
On shared hosting, several sites live on one server. Each site runs in its own isolated space, with its own files and its own databases. A problem at another customer gives no access to your site.
You choose your own PHP version
Per site and at any time. A recent PHP version receives security updates; an old one no longer does. So put your site on the newest version your theme and plugins support, and switch back if an update disappoints.
In transit: encrypted via SSL
Everything that travels between your visitor and your site — passwords, forms, orders — goes encrypted over https. Every hosting plan includes a free Let's Encrypt certificate that is renewed automatically. So there is no expiry date for you to watch.
If you want visitors to see in the certificate which company is behind the site, you can choose a paid certificate with organisation validation. For the encryption itself it makes no difference.
When things do go wrong
No security is complete. That is why what is ready for the moment things go wrong matters: a failed update, a human error or a hacked site.
Daily backup, 14 days
A backup of your files and your database is made every day and kept for 14 days. That is included; you do not need to set anything up.
Restore on request
Contact support with your domain name and the time when everything still worked. The more precisely you know that, the more targeted the restore can be. Do not keep working on the site in the meantime.
Monitoring and status page
We monitor our infrastructure and servers. If there is an outage or planned maintenance, you will see it on the status page, so you do not have to guess whether the problem is your site or us.
What you do yourself
Most incidents we see do not start at the server but in the website itself: a plugin that has not been updated for months, or a password that was also used elsewhere. These are the habits that make the difference.
Further reading
Where your data physically sits, what that means for the GDPR, and what we commit to regarding availability.