Free migrationsWe move your website for free: planned for zero downtime, handled by our engineers

Security

Every plan ships with security switched on.

Protection starts the day your site goes live, and isolation keeps other accounts away from your files.

Malware scanning on every plan WAF & DDoS mitigation Daily off-site backups Free auto-renewing SSL

What is running on your account right now, and what each piece stops.

Blue Arctic runs two hosting platforms, and they do not run the same software.

On Shared Web Hosting and Cloud Servers

Malware scanned and quarantined automatically (Imunify360)

Imunify360 scans every file write and locks infected files away, so an infection is contained rather than left to spread.

Known attack patterns blocked in front of your site (ModSecurity)

SQL injection, cross-site scripting, path traversal and brute-force login attempts. Its rule sets update continuously.

Each account walled off from the others (CloudLinux)

CloudLinux LVE containers give every account its own CPU, memory and process limits, enforced at the kernel level, the core of the operating system. CageFS keeps each account’s files out of view of the others. Activity in another account is contained rather than becoming your problem.

On Managed WordPress Hosting

A different platform with a different job, so it runs a different set of tools. Patchstack vulnerability protection, RapidMitigate virtual patching, a web application firewall, real-time malware scanning, and two-factor protection on WordPress logins. It reduces your exposure to known vulnerabilities. No security tool can make any website immune to every attack.

On both platforms

SSL issued and renewed for you, free

Visitors get the padlock in their browser and a private connection to your site. We issue and renew the certificate on every domain automatically. TLS 1.3 with TLS 1.2 fallback, and deprecated protocols disabled.

Daily off-site backups, retained for 30 days

We back up hosting accounts daily to separate infrastructure and keep 30 days of them, under our Terms of Service. On VPS the window is 5 days, held as 5 recovery points. Our engineers handle restores: open a ticket, and we will confirm the recovery point with you first. Backups are a safety net, not a certainty. Keep your own copies of anything business-critical.

Flood traffic filtered at the network edge

When someone floods your site with fake traffic to knock it offline, we filter that traffic at the network edge, before it reaches the server your site runs on. Very large attacks can still cause a brief interruption while mitigation engages.

Our hardware lives in a Tampa, FL datacenter, behind 24/7 monitored access control and camera coverage. The detail is on the infrastructure page.

None of it is an add-on, and there is no basic tier.

Already hacked, on any host? Emergency Malware Removal is $199 flat per incident. Our written guarantee: If we do not successfully remove the malware and secure the identified entry point, we refund the engagement in full. Clients who move to a monthly plan afterward receive the first month at no charge. Request emergency removal. Hardening your own server instead is Server Administration.

What we do when something is found.

  • We apply operating system and kernel patches proactively, and prioritise the critical and high-severity ones
  • Our team manages and tests control panel and PHP updates
  • Server health, file changes and unusual log activity are monitored around the clock
  • Confirmed threats are isolated and cleaned up, and we trace how they got in
  • Incidents follow a documented process: defined roles and escalation, triage, containment, root cause analysis, and a post-incident review
  • Security logs are retained for 90 days
  • Every administrative login to our infrastructure requires multi-factor authentication
  • Staff with infrastructure access have background checks and confidentiality agreements
  • We run regular vulnerability assessments and penetration testing

One thing to know up front. If a site hosted here is actively distributing malware, we may suspend it while we clean it up. Better you read that now than learn it mid-incident.

Structured network cabling in the Tampa, FL datacenter

Everything above is our side of the line

The server, the operating system, the security software, the network, the backups

This part stays yours

What none of that does is make a website immune to compromise

  • Keeping your own applications, plugins and passwords current still matters
  • Credential handling, and who has access to the account
  • Turning on two-factor authentication wherever your application offers it
  • Keeping your own copies of anything business-critical

Where we tell you a security patch, update or configuration change is needed and it is not applied, SLA Section 5 excludes service credits for problems that follow. Read the SLA.

Security is not compliance. Compliance is a separate engagement.

Standard plans are not HIPAA, PCI DSS, SOC 2, CJIS, or CMMC compliant environments. If your framework needs more than strong operational security, we build that as a custom engagement, scoped and quoted individually.

See how compliance engagements work

Questions about hosting security.

Does any of this cost extra?

No. Everything above is the default configuration on the cheapest plan and on the most expensive one, on both platforms.

What happens if malware is found on my site?

Infected files are quarantined automatically, and our engineers review flagged events rather than leaving them in a dashboard. We clean up what is confirmed and trace how it got in. A site actively distributing malware may be suspended while that work happens. If your site is hosted elsewhere and has already been hacked, Emergency Malware Removal is $199 flat, with no hosting plan required.

Does this make my site HIPAA or PCI compliant?

No. The standard security software is strong operational security, not a compliance environment. The compliance section further down this page lists the frameworks we build compliance engagements for, and how one is scoped.

Host somewhere security isn’t a line item.

Every plan ships with it. If your site is already in trouble, there is a fixed-price fix.

Security standard on every plan Daily off-site backups 24/7 helpdesk