If another site on my server is attacked, what happens to mine?
The design goal is containment. Every site runs inside its own CloudLinux LVE cage with capped CPU, RAM, IO, IOPS, processes and entry-processes, its own CageFS filesystem view, and per-site database throttling via MySQL Governor. An attacked site is throttled at its own ceiling rather than consuming the whole machine, and LiteSpeed per-IP connection limits bound how much of the web server it can hold. Containment is engineered at the kernel, not configured per customer.
Is DDoS protection included, or an add-on?
The baseline is included on every plan: LVE and CageFS isolation, LiteSpeed connection and request throttling, the Imunify360 network firewall, the proactive WAF and real-time malware scanning, with Cloudflare edge absorption and provider-level network filtering in front of the fleet. We include it because we cannot leave the protection of our own fleet optional. Advanced bot management, higher DDoS tiers, enhanced WAF rules and dedicated firewall rules are add-ons for sites that need them.
Will you take my site offline if it gets attacked?
Being a DDoS target maps to Cloudflare mitigation plus per-site rate limiting, and — only if the attack is threatening the origin — the 'throttled' state: tighter LVE limits with the site still up and serving. Throttled recovers automatically once the pressure clears. Suspension is reserved for non-payment or confirmed abuse, and even then the site serves a branded, reason-specific holding page rather than a broken one.
Does an application-layer flood still hit my database?
Not for anything served from cache. LSCache answers cached page requests without invoking PHP or MySQL, and a per-site Redis object cache offloads reads for genuinely dynamic pages. What remains is bounded by your site's LVE process and entry-process caps and by MySQL Governor's per-site database throttling, so database pressure from one site cannot spill onto the server. Cart, checkout, my-account and session pages stay uncached by default so hardening never breaks a transaction.
Can you protect traffic that is not HTTP?
Yes, at the network layer. Provider-level DDoS protection filters L3/4 floods upstream of our fleet regardless of protocol, and for advanced or enterprise requirements Cloudflare Magic Transit and Spectrum extend edge-grade mitigation to non-HTTP traffic.
How do I know an attack happened and what you did about it?
Every enforcement transition is logged with its reason, whether it was automatic or staff-initiated, and the evidence behind it. You are notified of what changed and what resolves it, every action is appealable, and privileged actions are audit-logged for your own compliance trail. Signals are aggregated in a single Abuse Desk rather than scattered across tools.
Can I try this before paying?
Yes. Footprint-Free Hosting starts with a card-free 7-day trial covering up to 5 sites — no payment details, no commitment. Plans are backed by a 30-day no-quibble money-back guarantee, free migrations and no vendor lock-in.