Trust & safety

Why you can trust your sites to Zinn Digital®

A registered UK company, an owned fleet, and more than 100,000 PBN sites hosted in-house across every niche. This page sets out exactly who you are buying from, how your sites are isolated and backed up, what happens when something goes wrong, and how you get your money back if it does.

  • 100,000+PBN sites hosted in-house
  • 30 daysNo-quibble money-back guarantee
  • 99.99%Uptime assurance
  • 16385785UK company number

A real company, with its name on the door

Zinn Digital LTD is registered in the United Kingdom under company number 16385785, at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. "Zinn Digital" is a registered trademark, number 018672629. Those details appear in the footer of every page on this site, in our legal terms and in our structured data — because a hosting company that will not say who it is should not be holding your network.

We are the operator, not a reseller. The fleet your sites run on is infrastructure we build, tune and own end to end, and it is the same infrastructure that already carries more than 100,000 PBN sites across every niche. There is no white-labelled upstream between you and your servers, and no third-party panel deciding what we are allowed to fix.

The company is led by founder and CEO Neil Lock, with 25+ years of full-stack engineering behind the platform. You can reach us by email at office@zinndigital.com, on Telegram at @zinndigital, or through support tickets from inside your dashboard.

Try it, and get your money back if it is not right

Trust is easier to extend when leaving is cheap. Every commercial term here is designed so the risk of trying us sits with us, not you.

A card-free trial

The 7-day Footprint-Free trial starts without payment details — no card, no authorisation hold, no silent conversion. It runs up to 5 sites so you can watch rotation and the footprint layer behave on a real network, then you choose whether to continue.

30-day no-quibble money-back guarantee

Paid plans carry a 30-day no-quibble money-back guarantee. "No-quibble" means what it says: you do not have to argue a case or pass a technical interrogation to get a refund inside the window.

Free migrations in

We move your existing sites in for you, with an automated migration that imports over a connector, FTP, cPanel or Plesk backup, or SSH, rewrites URLs, verifies the result and cuts DNS over — with rollback if the verification does not pass.

No vendor lock-in, by architecture

Every external dependency — payments, DNS, registrar, CDN, mail, AI — sits behind a swappable adapter, and nothing about your site is stored in a proprietary format that only our panel can read. Standard WordPress, standard databases, standard backups.

How your sites are kept apart from everyone else's

Shared infrastructure is only dangerous when it is shared badly. Isolation here is enforced by the kernel, not by good manners.

Per-site resource cages (LVE)

CloudLinux Lightweight Virtual Environments cap CPU, RAM, IO, IOPS, processes and entry-processes per site. A site that is attacked, or that runs away with a bad plugin, is throttled inside its own cage — so one bad neighbour cannot take the server down with it.

Filesystem isolation (CageFS)

Each tenant gets an isolated view of the filesystem and cannot see other tenants, other sites or sensitive system files. If a site is compromised, CageFS contains the breach rather than letting it walk across the machine.

Database throttling (MySQL Governor)

Per-site database usage is governed, so one tenant's heavy or badly-indexed queries cannot drag the server's performance down for everybody else on it.

Layered DDoS absorption

Volumetric and L7 floods are absorbed at the Cloudflare edge with per-site rate limiting and managed challenges, network-level protection sits underneath, and LiteSpeed connection throttling plus LVE entry-process limits keep a flood against one site contained to that site.

Security that is included, and security that is extra

We are explicit about the line, because "included security" that turns out to be a paywall is where most hosting trust dies.

  • Included on every plan: real-time malware scanning by Imunify360, across every site we host.
  • Included on every plan: the proactive WAF, which blocks exploit attempts against vulnerabilities before a patch exists.
  • Included on every plan: LVE and CageFS isolation, network firewalling, brute-force protection and IP reputation filtering.
  • Included on every plan: free SSL certificates, provisioned and renewed automatically across every account.
  • Upsold as an add-on: one-click malware cleanup and remediation — the fixing of an infected site, on a per-incident or subscription basis.
  • Upsold as an add-on: advanced protection tiers — enhanced WAF rules, priority scanning, bot management and higher DDoS tiers, dedicated firewall rules.
  • Why the baseline is free: an infected site threatens its neighbours and our IP reputation, so we cannot leave detection optional. Detection protects the fleet; remediation is work we do for you.

When something goes wrong

Backups only count if they survive the incident that made you need them, and enforcement only counts if it is predictable.

Daily backups, held 30 days

Every site is backed up daily and retained for 30 days, with one-click restore from the dashboard. You do not file a ticket and wait to get yesterday back.

Immutable, offsite, air-gapped

Per-site backups are written immutably to offsite object storage and air-gapped from the running fleet, with restores tested rather than assumed. Ransomware that reaches a site does not reach that site's history.

Graduated enforcement, not a kill switch

Instead of a single on/off suspension, sites move through reason-tracked states: throttled (tighter limits, site still up), restricted (outbound mail, cron or POSTs disabled, site still visible), suspended (offline behind a branded, reason-specific holding page), and quarantined (offline and locked for forensics).

Every transition is logged, notified and appealable

Each change records its reason, its evidence and whether a human or the policy engine made it; you are notified with what to do about it; and you can appeal. A suspension lifts on payment, fix or successful appeal, and a quarantine lifts after cleanup and review.

Accountability inside the platform

Trust is not only about outsiders. It is also about what we can see, what your team can do, and what is recorded.

Tenant isolation enforced in the database

Every record carries a tenant scope and PostgreSQL row-level security enforces it, so cross-tenant reads are blocked at the database rather than trusted to application code getting it right every time.

Strong authentication as standard

Identity runs on Keycloak: magic-link login by default, passkeys and WebAuthn, TOTP two-factor, social login, and SAML single sign-on for enterprise and agency customers — one login across the dashboard, the knowledge base and tickets.

Role-based team access

Memberships map a user to an organisation with a role — owner, billing, dev or read-only — so a billing contact never touches infrastructure and a read-only account cannot change anything. Organisations nest, so a reseller or agency parent scopes cleanly over its clients.

Audit logging on privileged actions

Every privileged and administrative action is written to an audit log with actor, action, target, evidence and IP — including anything our own staff do. Sensitive or destructive staff actions can require step-up authentication or two-person approval.

Secrets never live in code

Credentials are held in HashiCorp Vault and injected at runtime, never committed to a repository, baked into an image or written to a log line.

Scoped API access

API keys are issued per organisation with granular scopes — read-only, billing, provisioning — tied to the same permission catalogue as the dashboard, with sandbox keys kept separate from production.

Transparency you can check without asking us

Our status page runs on separate infrastructure, off-platform and independent of the fleet it monitors — because a status page hosted on the systems it reports on is worthless at precisely the moment you need it. It is fed by the same monitoring that drives our alerting.

Inside the dashboard you get per-site uptime monitoring, Core Web Vitals and performance data, error tracking, traffic and bandwidth, and resource usage measured against your entitlement. The numbers we act on are the numbers you can see, and alerts reach you through your chosen notification channels.

Our plans carry a 99.99% uptime assurance — that is the availability target the fleet is engineered and monitored against, stated as a commitment rather than as a historical scorecard.

Commercially, the same openness applies: prices are shown in your own currency as a stored, stable figure rather than a live exchange-rate guess, the platform speaks 58 languages, and plan inclusions are published rather than buried.

FAQ

Who am I actually buying from?

Zinn Digital LTD, a company registered in the United Kingdom under number 16385785, at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, led by founder and CEO Neil Lock. "Zinn Digital" is a registered trademark, number 018672629. We are the operator of the fleet, not a reseller of somebody else's.

Can another site on the same server compromise mine?

Isolation is designed to contain that, not to be hoped for. CageFS gives each tenant an isolated filesystem view so a compromised site cannot see other tenants' files, and LVE caps its CPU, memory, IO and process usage so it cannot starve its neighbours. No host can honestly promise zero risk on shared infrastructure — what we can tell you is that a breach is contained rather than free to spread, that real-time scanning and the proactive WAF run on every site, and that your backups are held immutably offsite and away from the running fleet.

Is malware removal included, or do I pay for it?

Detection is included and removal is an add-on. Every plan includes real-time Imunify360 malware scanning, the proactive WAF that blocks exploits before a patch exists, LVE and CageFS isolation, network firewalling and brute-force protection. One-click malware cleanup and remediation is sold separately, per incident or by subscription, as are advanced protection tiers such as enhanced WAF rules, bot management and higher DDoS tiers.

What happens if my site gets suspended?

Enforcement is graduated and reason-tracked rather than a single switch. A site may first be throttled with tighter resource limits while staying online, then restricted with outbound mail, cron or POST requests disabled while still being visible, then suspended and served a branded holding page that states the reason, and in confirmed malware or phishing cases quarantined with files locked for forensics. Every transition is logged with its reason and evidence, you are notified with the steps to resolve it, and you can appeal. A suspension is lifted on payment, fix or a successful appeal; a quarantine is lifted after cleanup and review, not automatically.

How do I get my money back if it does not work out?

Paid plans carry a 30-day no-quibble money-back guarantee, so you can ask inside the window without having to argue a case. Before that, the 7-day Footprint-Free trial starts card-free with up to 5 sites, so most people never need to pay to find out whether the platform suits them.

If I leave, am I stuck?

No part of your site is held in a format only our panel can read — you run standard WordPress or static HTML, on standard databases, with standard backups you can restore from. Architecturally, every external dependency we use sits behind a swappable adapter, which is the same discipline applied to ourselves: we build so that nothing, including us, becomes a component you cannot replace.

Can I see whether the platform is up without contacting support?

Yes. Our status page runs on separate infrastructure off the platform it reports on, fed by the same monitoring that drives our alerting, and your dashboard shows per-site uptime, Core Web Vitals, error tracking and resource usage against your entitlement. Plans carry a 99.99% uptime assurance as the target the fleet is engineered and monitored against.

Check us out at our expense, not yours

Start a card-free 7-day trial with up to 5 sites — no payment details, no commitment. Paid plans are covered by a 30-day no-quibble money-back guarantee, with free migrations in and no vendor lock-in.

Start free