Security
What we secure, and what stays with you
What every plan guards by default, how payment data stays out of our hands, where your files physically sit, how to disclose a flaw — plus an honest split of the risks we carry and the ones you do.
On Every Plan
Nothing extra to buy, because the security is already inside
Every control listed here comes with every plan, down to the cheapest. Nothing below costs a penny extra.
HTTPS settled before you arrive
A free SSL certificate goes out for every name you hold, and it renews itself well before expiry. Nothing to configure, nothing to diarise, nothing to pay.
Hostile traffic cut off early
Malicious requests are stripped out before your account ever sees them, first by DDoS mitigation at network level and then by a web application firewall standing behind it. A flood aimed at your site never manages to take it off the air.
Malware found without your looking
Imunify360 works away in the background, flagging known malware and file changes that look wrong, so a poisoned plugin gets caught instead of festering.
Restores you run yourself
Every plan takes an automatic copy each day, and the higher tiers take one more often than that. Restores run from the control panel, and no ticket is needed.
Accounts sealed from each other
Accounts on the shared platform each run in isolation from one another, so a site breached elsewhere on that machine never turns into your emergency.
Your card never reaches us
Payment details are collected and stored by Stripe. All that stays with us is a token and the final four digits, which leaves no card number on our side for anyone to steal.
Complete List
Running from day one
- Self-reissuing free SSL for each name
- Network-level DDoS mitigation
- A web application firewall out front
- Malware detection through Imunify360
- An automatic copy taken daily
- Self-service restores from the panel
- Isolation between shared hosting accounts
- Two-factor authentication on your login
- Defences against brute-force logins
- Current PHP releases, security patches applied
Disclosure
Found a weakness? Report it.
We would far rather the first report of a flaw came from you than from a headline.
Send info@hosting-n-domains.com enough detail for the finding to be reproduced. We confirm receipt, then keep you posted while the fix is prepared and released.
Give us a fair window to close the issue before you publish anything, and keep your testing well clear of other customers. That means no denial-of-service runs, and no reaching into data that belongs to somebody else. There is no paid bounty programme here, so no reward is guaranteed, though credit is yours if you would like it.
Report phishing, spam or malware on a site we host to report abuse instead of this address. On data protection matters, read our privacy policy.
Common Questions
Security, answered plainly
How safe are my card details here?
Card details go directly to Stripe, one of the largest payment processors anywhere, and they remain on Stripe's infrastructure rather than ours. What reaches our side is a payment token together with the last four digits. Never the full number. Never the security code either. The reason that design matters is as much practical as technical: were somebody to break into these machines tomorrow, there would be no card numbers sitting there to take.
What is your position on PCI compliance?
Responsibility for PCI is shared out, so the honest answer depends on which piece you have in mind. Card handling sits wholly on Stripe's side and never touches our servers, which puts those obligations with Stripe, and Stripe holds PCI DSS Level 1 certification. Your own shop works the same way. Route payments through a gateway such as Stripe or PayPal, one that handles cards on its own machines, and you drop into the lightest PCI band, normally a short self-assessment questionnaire. What we supply is the encrypted, isolated, monitored platform underneath your site. What you supply is patched software and admin passwords deserving of the name.
Do you hold ISO 27001, SOC 2 or any similar certification?
No, and saying so outright beats dancing around the question. Hosting & Domains is a small, young company, and neither ISO 27001 nor SOC 2 has been gone through here. Both are serious undertakings. Claiming either one without holding it would be considerably worse than admitting we do not have it. What sits in their place is this: a legal identity you can check for yourself, a named upstream platform, the particular controls written out on this page, and a disclosure route that genuinely works. Where certification is a hard requirement on your side, you will be told plainly that this is the wrong provider for you, instead of having your time wasted.
Where does my data actually live, and who can get at it?
Your files and your databases sit inside a London facility. Access is confined to staff who need it, either to keep the platform running or to answer a ticket you have raised. No customer information is ever sold, and your content serves no purpose here beyond running the service you pay for. All the legal detail lives in our privacy notice: the lawful basis for each kind of processing, how long things are retained, and which sub-processors are involved.
How do I report a vulnerability?
Send the specifics to info@hosting-n-domains.com and the report gets acknowledged. We ask for a reasonable window to investigate and ship a fix before anything goes public, and for testing that never degrades service for other customers or reaches data that is not yours — so no denial-of-service attempts and no probing of other accounts. There is no paid bounty here and no reward can be promised, though credit is yours for the asking, and you will hear how the fix progresses.
Which parts of this are mine to handle?
Defending the platform falls to us: server, network, firewall, malware scanning, copies, encryption. Whatever you put on top of it belongs to you. In practice that means keeping WordPress, plugins and themes patched, using strong unique passwords with two-factor switched on, deleting plugins you no longer run, and thinking twice before installing anybody's code. Almost every compromised site that lands on our desk was entered through an outdated plugin or a recycled password, never through the server itself.
And if my site gets compromised regardless? What then?
Open a ticket and we start work. The order runs roughly like this: work out how they got in, restore from a clean copy taken before the infection landed, then shut the hole so the same trick fails a second time. That is precisely why an automatic daily copy is worth more than any single preventative layer. Recovery is the part that genuinely saves you. And if the cause turns out to be an abandoned plugin or a feeble password, you will be told so in plain words, because otherwise you are back in the same position inside a month.
Protection that comes as standard.
Every plan — even the $2.42 one — carries SSL, DDoS filtering, malware scanning and a daily copy.
See Hosting Plans