lbreeze

The parts of this a review can actually check.

A security page is usually a list of adjectives and a logo of a standard. This one is the mechanisms — where the boundaries are, what happens to your backups, how a machine gets patched, and what an entry in our audit log would have to survive to be changed. At the end is the list of things we are not claiming.

Send us your questionnaire
THE AUDIT LOG, SEALEDinvoice.paidprev 3f9c… · self 8a21…service.provisionedprev 8a21… · self c47d…access.grantedprev c47d… · self 1b6e…each row carries the hash of the one before itso changing one breaks verification of every row after itillustrative hashes

Isolation

Where the boundaries are, and why there.

Most of what makes a shared platform safe is decided before anything is running on it. These are the lines, and the reason each one is drawn where it is rather than somewhere cheaper.

The website is the unit, not the account

One unprivileged, user-namespace-remapped container per site. A customer with five sites has five boundaries, so a compromise of one does not reach the other four — which is not true of a platform that isolates per account.

Databases get their own user and grants

A per-customer database, user and grants on nodes that do nothing else. The panel's database manager runs every query as your own database user, so your permissions are the boundary rather than an application's idea of them.

No phpMyAdmin anywhere

A PHP application with one of the longest CVE histories in hosting, holding database credentials, presented as a second authentication surface. We do not run one, and the panel's own tool is not a replacement pretending otherwise.

Mail runs on its own machines

Different sending reputation, a different scaling curve and a different attack surface from a web node. Putting mail on a web node turns any one of those three problems into all three.

Configuration is never edited in place

A change is rendered to a staging directory, validated, and then swapped in, with the previous version kept for rollback. A configuration that would not start is refused before it takes a machine down.

Hand edits are undone and reported

Each machine compares what is actually on it against what it is meant to be running, every cycle. Something changed by hand at two in the morning is put back, and it appears in the report rather than being noticed months later.

Your account

What protects the login itself

The parts you control, all of them in the client area rather than behind a support request.

  • Two-step sign-in A one-time code after your password, on accounts that have it turned on.
  • Sessions you can see and end Every active session listed, with the ability to revoke one you do not recognise without changing your password first.
  • Sign-in history Every attempt, successful or not, with the address, the device and the time — and the country where that can be resolved. An unfamiliar sign-in is something you can see rather than something you are told about later.
  • A trusted address list Restrict sign-in to addresses you nominate, managed by you.
  • Access granted per thing Someone can hold your DNS without also holding your billing, your mailboxes or your files. A web developer does not need the keys to everything to change a record.
  • An audit log that is sealed Administrative events are hash-chained: each row carries the hash of the one before it and the chain is sealed periodically. A row cannot be altered or removed after the fact without verification of everything after it failing.

None of this is an add-on tier. It is the same account security on the smallest plan as on the largest, because an account is worth exactly as much to whoever takes it either way.

If your own policy needs something stricter than this list, say so before you buy rather than after.

In transit

Encryption where it is actually decided.

A certificate on everything

Issued and renewed for every website and every mail domain, terminated at the edge along with rate limiting. You will not get the expiry email, because there will not be one.

Mail that does not fall back quietly

MTA-STS and DANE, so your mail is delivered over an encrypted connection rather than one that silently drops to plain text when the other end misbehaves.

SPF, DKIM and DMARC from the start

The records that tell other servers your mail is really yours, in place before the first message rather than after somebody's reply bounces.

Signing keys that rotate

DKIM keys rotate on a schedule, because a key that never changes is the one that eventually leaks and then cannot be quietly retired.

HTTP/3 refused where it does not work

Enabled only where a machine can genuinely serve it. Half-enabling it is the kind of optimisation that takes every site on a box down with it.

Consent recorded, not assumed

Cookie consent on this site keeps an auditable record of each decision, so what you chose is a row rather than a banner that went away.

Recovery and patching

The two things that decide how a bad day ends.

Backups leave the machine

Written to object storage with keys held per tenant, because a backup that lives on the box it is protecting is not a backup. Daily, kept fourteen days.

And they are replayed

Restores are rehearsed on a schedule, so a backup is known to work before the day you need it rather than assumed to. One that has never been proven is reported as never proven rather than counted beside one that has.

Restoring is yours to do

A button in the panel, not a ticket and a wait. The whole value of a backup is how quickly you can use it.

Every machine reports its own state

Reachability, patch state and CVE exposure from the moment a machine exists — including a machine you administer yourself on a cloud server, which is still one you can see.

CVEs matched to what is installed

Against each host's real package inventory at the version it actually has, not a guess from the operating system name. A stale inventory is refused rather than matched and reported as clean.

Our own updates are signed

Zephyr, kstack and Standby come down a licence-gated release edge, Ed25519-signed and verified against a pinned key before anything is swapped in. Nothing is trusted because it downloaded without error.

Frequently asked questions

Do you hold ISO 27001, SOC 2 or Cyber Essentials?

We do not claim a certification anywhere on this site, and you should not infer one from anything on this page. If a certificate is a hard requirement of your procurement, ask us at the start rather than after you have worked through a questionnaire — you will get a straight answer either way.

Is my data encrypted at rest?

Backups are written to object storage with keys held per tenant. Beyond that, ask us about the specific product you are buying and you will get a specific answer, because a blanket assurance on a web page is exactly the kind of claim that turns out to have an exception in it.

Where is my data processed?

Ask before you order if it matters to you, and we will answer for the products you are actually buying rather than in general terms. If the answer has to be a particular country, that is a question worth settling first.

Can I have your data processing addendum and sub-processor list?

Ask and we will send the current versions. The sub-processor list is the one worth reading closely, because it is the part that names who else is involved.

How do I report a vulnerability?

Get in touch before you go looking. The acceptable use policy sets out what you are permitted to test and how to make contact first, and we would very much rather hear from you than work it out from the logs.

Can I run my own security scan against my site?

Against your own services, with prior contact, yes — the terms are in the acceptable use policy. The reason for asking first is that an unannounced scan looks exactly like the thing we are meant to stop, and stopping it is what will happen.

What are you responsible for and what am I?

On web hosting the operating system is ours to patch; on a cloud server it is yours, along with your firewall rules, your runtimes and your application. That line is drawn on the cloud servers page in advance rather than during an incident, and the support page sets out the rest of it.

The policies themselves

What we collect and why, and what you are permitted to do on the platform. These are the documents that bind rather than describe.

Privacy policy

Send us the questionnaire.

If your organisation has one, send it rather than working through this page and guessing. Anything we cannot answer honestly, we will say we cannot answer rather than fill in the box.

Get in touch