Security
Security switched on before your site goes live.
Malware scanning, a firewall and free SSL run from day one, with no security tier to buy. The tools differ by product, and each one is listed below.
- Malware scanning
- Web application firewall
- DDoS filtering at the network edge
- Free auto-renewing SSL
What runs on each product
Blue Arctic runs two hosting platforms, and they don’t run the same software.
Shared Web Hosting and Cloud Servers
- Malware scanning (Imunify360). Every file write is scanned, and infected files are quarantined automatically so an infection is contained.
- Web application firewall (ModSecurity). Blocks SQL injection, cross-site scripting, path traversal and brute-force logins, with rule sets that update continuously.
- Account isolation (CloudLinux). Each account gets its own CPU, memory and process limits, enforced by the operating system, and CageFS keeps its files out of view of the others.
Managed WordPress Hosting
- Patchstack vulnerability protection, with RapidMitigate virtual patching for known plugin and theme flaws.
- A web application firewall and real-time malware scanning.
- Two-factor protection on WordPress logins.
On both platforms
- Free SSL, issued and renewed automatically on every domain. TLS 1.3 with TLS 1.2 fallback, and deprecated protocols disabled.
- Flood traffic filtered at the network edge, before it reaches the server your site runs on. Very large attacks can still cause a brief interruption while mitigation engages.
Backups
- Shared Web Hosting: daily, to separate off-site infrastructure, kept for 30 days under our Terms of Service.
- Managed WordPress Hosting: daily, kept for 30 days. Restore one yourself from the control panel, or ask the helpdesk.
- VPS: daily, with 5 recovery points.
For an engineer-run restore, open a ticket and we’ll confirm the recovery point with you first. Backups are a safety net, not a certainty, so keep your own copies of anything business-critical. Backups answer data loss; redundancy answers downtime.
Security is not compliance. Standard plans are not HIPAA, PCI DSS, SOC 2, CJIS, or CMMC compliant environments. If your framework needs more than strong operational security, we build that as a custom engagement, scoped and quoted individually. How compliance engagements work.
Our side and yours
What we do
- Apply operating system and kernel patches proactively, critical and high-severity first
- Manage and test control panel and PHP updates
- Monitor server health, file changes and unusual log activity around the clock
- Isolate and clean up confirmed threats, and trace how they got in
- Require multi-factor authentication for every administrative login to our infrastructure, and keep security logs for 90 days
What stays yours
None of this makes a website immune to compromise
- Keeping your own applications, plugins and passwords current
- Credential handling, and who has access to the account
- Turning on two-factor authentication wherever your application offers it
- Keeping your own copies of anything business-critical
Where we tell you a security patch, update or configuration change is needed and it is not applied, SLA Section 5 excludes service credits for problems that follow. Read the SLA. For the same split worked through layer by layer, using the May 2026 kernel patches as the example, see what your host patches and what stays with you.
Security questions
What security is included with my hosting?
It depends on the product, and each one is listed on this page. Every product has malware scanning, a web application firewall, free SSL and edge DDoS filtering switched on before your site goes live. None of it costs extra or is sold as a separate tier.
What happens if malware is found on my site?
Infected files are quarantined automatically, and our engineers review flagged events rather than leaving them in a dashboard. We clean up what is confirmed and trace how it got in. A site actively distributing malware may be suspended while that work happens. If your site is hosted elsewhere and has already been hacked, Emergency Malware Removal is $199 flat, with no hosting plan required. Our written guarantee: If we do not successfully remove the malware and secure the identified entry point, we refund the engagement in full.
Does this make my site HIPAA or PCI compliant?
No. The standard security software is strong operational security, not a compliance environment. The compliance note on this page explains how a compliance engagement is scoped.
Security comes with the hosting
Already hacked, on any host? Emergency Malware Removal is a fixed-price fix, with no hosting plan required.
