For security teams

WordPress hosting that answers to your security review.

Security teams are rarely the ones choosing the host and always the ones signing off on it. The questions you have to answer are about evidence, isolation and how fast a CVE gets patched.

Exportable audit trailSSO and 2FA enforcedIsolated containers
Audit loggingSSO + 2FAContainer isolationManaged WAFDaily backups24/7 support
Built for review

Everything a security review asks of a host.

Not a feature list — the specific things a reviewer asks for evidence of, and where that evidence comes from.

Every administrative action is recorded

Logins, plugin changes, user role edits and file writes are logged with actor and timestamp, and the log is exportable rather than only viewable in a dashboard.

Actor and timestampExportable

Access you control centrally

Single sign-on with enforced two-factor, per-user roles, and one-click admin login that leaves a record instead of a shared password in a password manager.

SSOEnforced 2FA

One compromised site is one compromised site

Each site runs in its own container with its own filesystem and database credentials, so lateral movement between sites on the same account is not a path that exists.

A named window for patching

Core and plugin vulnerabilities are patched to a committed timeline rather than to best effort, and the change is visible per item rather than as a single 'updated' flag.

Backups you can prove restore

Daily snapshots replicated off the origin, with restores you can rehearse on staging rather than discover the state of during an incident.

Evidence

The things a reviewer asks to see.

Most hosting security pages describe controls. What a review actually needs is the artefact — the log, the isolation boundary, the retention setting.

  • Exportable audit log with actor and timestamp
  • SSO and enforced two-factor on all accounts
  • Per-site isolation, no shared credentials
  • Documented retention and restore rehearsal
Audit log
Exported to your SIEM
streaming
Two-factor
Enforced on all accounts
12/12
Vulnerability patches
Within committed window
current
Restore rehearsal
Run on staging
scheduled
Isolation

Blast radius, measured.

The security question that matters is not whether a site can be compromised but what a compromise reaches. Isolation is what decides that.

Per-site
containers and credentials
Daily
offsite replicated backups
24/7
response, not a queue
MagicWP1 ms
Shared account, one filesystem40 ms
Shared database user across sites18 ms

Illustrative comparison of how many sites a single compromised install can reach. Lower is better; one means itself only.

Configuration

What we configure for a security team

These differ from a standard site on the same plan, and each exists because somebody has to produce evidence for it during a review.

SettingWhat we doWhy
Audit log exportStreamed to your own collector rather than held only in our dashboardEvidence that lives exclusively in a vendor's interface cannot be correlated with the rest of your estate, and it disappears at exactly the moment a dispute about the vendor makes it most relevant.
Authentication policySSO with two-factor enforced at the account level, not per userA control that individual users may opt out of is not a control a reviewer can accept, because its coverage is a matter of habit rather than of configuration.
Credential scopeSeparate database users and filesystem boundaries per siteSharing one database account across an estate means the impact of a single leaked credential is the whole estate, which turns a routine plugin vulnerability into an account-wide incident.
Patch windowCommitted remediation timeline per severity, with per-item statusBest-effort patching cannot be evidenced, so a reviewer has no way to distinguish a host that patched within a day from one that happened not to be targeted yet.
Backup retentionRetention period set explicitly and restores rehearsed on stagingA backup nobody has restored is an assumption rather than a control, and an incident is the worst possible moment to discover which of the two you had.
Plans

Simple, transparent pricing.

Every plan includes free migration, daily backups, SSL and 24/7 support.

MonthlyYearly
Starter
For personal sites, blogs, and portfolios.
$20/mo
Billed $240 yearly · save $60
  • 1 WordPress site
  • 10 GB NVMe disk
  • Free SSL
  • Daily backups
  • One-click deployment
  • Support tickets
Start free trial
Pro★ Most popular
For growing businesses and busy stores.
$80/mo
Billed $960 yearly · save $240
  • 5 WordPress sites
  • 50 GB NVMe disk
  • Free SSL
  • Daily backups
  • One-click deployment
  • Priority support tickets
Start free trial
Enterprise
For agencies and high-traffic platforms.
$250/mo
Billed $3000 yearly · save $600
  • 20 WordPress sites
  • 200 GB NVMe disk
  • Free SSL
  • Daily backups
  • One-click deployment
  • Dedicated support
Start free trial
FAQ

Questions, answered.

Can we export audit logs to our own SIEM?
Yes. Administrative actions are recorded with actor and timestamp and streamed to your collector, because evidence held only in a vendor dashboard cannot be correlated with the rest of your estate.
How are sites isolated from each other?
Each runs in its own container with its own filesystem and its own database credentials. A compromise of one site does not have a path to the next one on the same account.
What is your patching timeline for a WordPress CVE?
A committed window by severity rather than best effort, with the status visible per item. That distinction matters in a review: best-effort patching produces no evidence either way.
Can you enforce SSO and two-factor for everyone?
Yes, at the account level rather than per user. A control individual users can opt out of is a habit, not a control, and reviewers treat it accordingly.
Do you support penetration testing?
Yes, with a scheduling window agreed in advance so your test is not mistaken for the thing it is simulating and blocked by the WAF partway through.

Hosting your security team can actually sign off.

Exportable evidence, real isolation, and a patch window with a number attached.