Security & isolation

Security that contains problems before they spread

Every site we host runs inside its own kernel-level cage, watched by a proactive firewall and real-time malware scanning. One compromised or attacked site cannot see its neighbours, drain the server, or drag anyone else down. This is the same stack that keeps 100,000+ PBN sites online across every niche, and the baseline is included on every plan.

  • 100,000+PBN sites hosted across every niche
  • 99.99%uptime target
  • Real-timemalware scanning included
  • Includedisolation, WAF and scanning baseline

Isolation at the kernel, not just the config file

CloudLinux LVE and CageFS give each site its own resource cage and its own filesystem view. A runaway process, a traffic spike or a breach is contained inside that cage instead of spilling onto the server.

Per-site resource caps (LVE)

Lightweight Virtual Environments cap CPU, RAM, IO, IOPS, processes and entry-processes per site. A site under attack or running away is throttled inside its own cage, so one bad neighbour cannot take down the server.

Filesystem isolation (CageFS)

Each tenant gets an isolated filesystem view and cannot see other tenants, other sites, or sensitive system files. A breach on one site is contained, not shared.

Per-site database throttling (MySQL Governor)

CloudLinux MySQL Governor throttles per-site database usage, so one site's heavy queries cannot slow the server for everyone else. Redis object cache offloads read pressure on top.

Hardened per-site PHP

CloudLinux alt-PHP gives each site its own version selector, its own extensions and hardened settings, with LSAPI workers bounded by the site's LVE limits.

Malware and exploit defence, always watching

Imunify360 runs on every worker as a single integrated layer: it looks for compromise, blocks exploits before they land, and can clean an infection in one click.

  • Real-time malware scanning on every site, included on every plan — because an infected site threatens its neighbours, the server's reputation and our IP ranges.
  • A proactive WAF that blocks known exploits before a patch is even available, plus a network firewall, brute-force protection and IP reputation filtering.
  • One-click malware cleanup and remediation when something does get through — available per incident or as a subscription.
  • Suspected compromises are cross-checked against Google Safe Browsing, PhishTank and SURBL/APWG blocklists, and correlated with mail-log anomalies to catch spam-sending sites early.

Layered DDoS defence, so one attack is not everyone's outage

Volumetric floods are absorbed at the edge, network-level attacks are filtered upstream, and the server layer contains whatever reaches it. An attack aimed at one site stays that site's problem.

Edge (L7)

Cloudflare absorbs volumetric floods with an L7 WAF, per-site rate limiting, bot management and managed challenges before traffic ever reaches origin.

Network (L3/4)

Provider-level DDoS protection filters network-layer floods upstream of the fleet, with advanced enterprise mitigation available for high-risk sites.

Server

LiteSpeed connection and request throttling, Imunify360's network firewall, per-IP connection limits and LVE entry-process caps keep a flood against one site contained to that site's cage.

Baseline included, advanced protection when you need it

The essentials protect the whole fleet, so they are never optional. Heavier protection is there to buy when a site's risk profile calls for it.

  • Included for everyone: LVE and CageFS isolation, the proactive WAF, and real-time malware scanning.
  • Upsold as add-ons: one-click malware cleanup and remediation, enhanced WAF rules, priority scanning, bot management and higher DDoS tiers, and dedicated firewall rules.
  • Enforcement is graduated and reversible: instead of a blunt on/off suspend, sites move through throttled, restricted and suspended states, each logged with a reason, notified to you, appealable, and auto-recovering once the cause clears.
  • Suspended sites show a branded, reason-specific holding page rather than a broken one, and every privileged action is audit-logged for your compliance trail.
  • Per-site backups are immutable, offsite and air-gapped, with tested restores — so even a worst-case compromise is recoverable.

FAQ

Is security included, or is it an expensive add-on?

The baseline is included on every plan: LVE and CageFS kernel-level isolation, the proactive WAF, and real-time malware scanning. We include these because an infected or abusive site threatens its neighbours and our IP reputation, so we cannot leave protection optional. One-click cleanup, enhanced WAF rules, priority scanning and higher DDoS tiers are available as add-ons when a site needs them.

If one site on the server is attacked or hacked, does it affect mine?

No. Every site runs inside its own CloudLinux LVE resource cage and CageFS filesystem view. A runaway, attacked or compromised site is throttled and contained inside its own cage — it cannot see your files, drain shared resources, or take the server down. MySQL Governor applies the same per-site limits to database load.

What happens if my site does get infected with malware?

Imunify360 scans in real time and flags the compromise immediately. You can trigger a one-click cleanup to remediate it, and severe or unresolved cases are quarantined offline with files locked so the infection cannot spread while evidence is preserved. Because backups are immutable, offsite and air-gapped, a clean restore is always available as a fallback.

How do you handle DDoS attacks?

Defence is layered. Cloudflare absorbs volumetric and L7 floods at the edge with per-site rate limiting and bot management; provider-level protection filters network-layer attacks upstream; and at the server, LiteSpeed throttling, the Imunify360 firewall and LVE entry-process caps keep a flood against one site contained to that site. Advanced bot management and DDoS tiers are available for higher-risk sites.

What is the proactive WAF and how is it different from a normal firewall?

Imunify360's proactive WAF blocks known exploit techniques before a patch exists for the underlying vulnerability, rather than only reacting to signatures after the fact. It sits alongside a network firewall, brute-force protection and IP reputation filtering, all included on every plan.

Hosting that defends itself, from the first site

Kernel-level isolation, a proactive WAF and real-time scanning are on the moment you deploy. Try it with a card-free 7-day trial, backed by a 30-day money-back guarantee, free migrations and no vendor lock-in.

Start free