Security
The line between our job and yours
Every plan's built-in protections, how payment data stays out of our hands, where your files physically sit, how to disclose a flaw — plus an honest split of the risks we carry and the ones you do.
On Every Plan
No security add-ons to buy — it's all in
Each control listed here ships with every plan, right down to the cheapest. Nothing below costs a cent extra.
HTTPS sorted before you arrive
Each domain is issued a free SSL certificate automatically, and it renews itself ahead of expiry. No setup, no calendar reminder, no charge.
Hostile traffic cut off early
Network-level DDoS mitigation and a web application firewall strip out malicious requests before they touch your account, so a flood aimed your way never takes the site down.
Malware found without you looking
Imunify360 runs quietly in the background, flagging known malware and suspicious file changes, so a poisoned plugin gets caught rather than left festering.
Restores you run yourself
Automatic daily backups on every plan — more frequent on the higher tiers — restorable straight from the control panel with no ticket needed.
Accounts sealed from each other
On the shared platform every account runs in isolation, so a breached site elsewhere on the server never becomes your emergency.
Your card never reaches us
Stripe collects and stores all payment details. We keep only a token and the final four digits — there is no card number on our side for anyone to steal.
Complete List
Running from day one
- Self-renewing free SSL for each domain
- Network-level DDoS mitigation
- A web application firewall out front
- Malware detection by Imunify360
- Automatic backups running daily
- Self-service restores from the panel
- Isolation between shared hosting accounts
- Two-factor authentication on your login
- Defences against brute-force logins
- Current PHP releases, security patches applied
Disclosure
Spotted a weakness? Report it.
We'd much rather the first report of a flaw came from you than from a headline.
Send info@hostingfastnet.com enough detail for us to reproduce what you found. We will confirm receipt and keep you posted while the fix rolls out.
Give us a reasonable window to close the issue before publishing, and keep your testing clear of other customers — no denial-of-service runs, and no reaching for data that belongs to someone else. We run no paid bounty, so a reward is not guaranteed, but credit is yours if you would like it.
Phishing, spam or malware on a site we host should go to report abuse rather than here. For data protection questions, see our privacy policy.
Common Questions
Security, answered plainly
How safe are my card details here?
Card details travel straight to Stripe — among the biggest payment processors in the world — and stay on Stripe's infrastructure, not ours. Our systems receive only a payment token and the final four digits: never the complete number, never the security code. That design matters practically as much as technically. Were our servers broken into tomorrow, an attacker would find no card numbers to walk away with.
What's your position on PCI compliance?
PCI splits into shared responsibilities, so the straight answer depends on which piece you mean. Card handling happens entirely on Stripe's side and never crosses our servers, placing those obligations with Stripe — who carry PCI DSS Level 1 certification. Your own store follows the same logic: route payments through a gateway such as Stripe or PayPal that processes cards on its own infrastructure and you fall into the lightest PCI bracket, normally a brief self-assessment questionnaire. Our part is the encrypted, isolated, monitored platform beneath your site. Yours is keeping software patched and admin passwords strong.
Do you hold ISO 27001, SOC 2 or similar certifications?
We don't, and we would rather state it than dance around it. HostingFast is small and young, and we have not been through ISO 27001 or SOC 2 — both are serious undertakings, and claiming them without holding them would be far worse than admitting we lack them. What we can offer instead is a verifiable legal identity, a named upstream platform, the concrete controls documented on this page, and a disclosure channel that genuinely works. If certification is a hard requirement on your side, we will say plainly that we are not the right provider rather than burn your time.
Where is my data stored, and who can get at it?
Site files and databases are held in a London datacentre. Only staff who need access to operate the platform or handle the support requests you raise can reach them. Customer data is never sold, and your site content is used for nothing beyond running the service. The legal detail — lawful basis for processing, retention periods and the sub-processors involved — lives in our privacy policy.
What's the process for reporting a vulnerability?
Write to info@hostingfastnet.com with the specifics and we will acknowledge the report. We ask for a reasonable window to investigate and ship a fix before anything goes public, and for testing that never degrades service for other customers or reaches data that isn't yours — so no denial-of-service attempts and no probing of other accounts. We run no paid bounty and cannot promise a reward, but we will credit you if you'd like, and we will keep you informed as the fix goes in.
Which parts of security are down to me?
The platform is ours to defend: server, network, firewall, malware scanning, backups and encryption. Whatever you deploy on it is yours. In practice that means keeping WordPress, plugins and themes patched, using strong unique passwords with two-factor switched on, removing plugins you no longer run, and thinking twice about any code you install. Nearly every hacked site we deal with was not breached through the server — the way in was an outdated plugin or a recycled password.
Suppose my site gets compromised anyway — then what?
Raise a ticket and we are on it. The usual sequence: establish how they got in, restore from a clean backup taken before the infection, then seal the hole so the same trick fails next time. It is exactly why daily automatic backups outweigh any single preventative layer — recovery is the part that genuinely rescues you. And if the root cause turns out to be an abandoned plugin or a weak password, we will tell you straight, because otherwise you will be back within the month.
Protection that comes as standard.
Every plan — even the $2.42 one — carries SSL, DDoS filtering, malware scanning and daily backups.
See Hosting Plans