CloudPerch
HostingSupportHow It WorksPricingDomainsFAQ
Sign inGet started
HostingSupportHow It WorksPricingDomainsFAQSign in
Security

Security at CloudPerch

Security is built into how CloudPerch runs — isolated sites, encrypted data, daily backups, and continuous monitoring, so your site stays on safe high ground.

Last updated · 1 June 2026

On this page
Our approachInfrastructure & isolationEncryptionNetwork & DDoS protectionBackups & recoveryAccess controlMonitoring & patchingResponsible disclosureIncident responseOur commitmentsContact

Our approach

Security is not a bolt-on at CloudPerch — it's part of how the platform is built. Every site we host runs on hardened nodes with sensible defaults already in place, so you don't have to be a security engineer to run a safe website. We'd rather ship a platform that's safe out of the box than hand you a checklist.

We design with a few plain principles: isolate everything we reasonably can, keep the smallest amount of data we need, encrypt it coming and going, and assume things will eventually go wrong so recovery is always close at hand. The sections below describe the practices we hold ourselves to.

Infrastructure & isolation

Sites that share a node should never share a fate. On CloudPerch, each site runs under its own dedicated system user with its own separate PHP-FPM pool, so one site can't read, write, or starve the resources of another. A compromise of one tenant stays contained to that tenant.

  • Per-site system users — file ownership and permissions are scoped to a single site, not shared across the box.
  • Isolated PHP-FPM pools— separate process pools mean noisy or misbehaving neighbours can't reach into your code or your traffic.
  • Hardened nodes — our LiteSpeed + NVMe servers run a minimal, locked-down configuration, with unnecessary services disabled and firewalls in front of every host.
  • Least exposure — only the services that need to face the internet do, and administrative access is kept off the public network wherever possible.

Encryption

We encrypt your data both while it travels and while it sits still. Every site we host gets free, auto-renewing SSL/TLSso traffic between your visitors and our edge is encrypted by default — there's nothing to buy, install, or remember to renew.

  • In transit — modern TLS protects traffic to your site and across the CloudPerch network, and certificates renew automatically before they expire.
  • At rest — data stored on our infrastructure, including backups, is encrypted at rest.
  • Secrets — credentials and API keys are stored encrypted and accessed only by the services that need them, never logged in plain text.

Network & DDoS protection

Your site sits behind our global CDN spanning 12 edge regions, which does more than make pages fast — it acts as a buffer between attackers and your origin. Malicious traffic is absorbed and filtered at the edge before it ever reaches the node your site runs on.

  • DDoS mitigation — volumetric and application-layer attacks are detected and dropped at the edge, keeping your site reachable for real visitors.
  • Edge filtering — obvious bad actors and abusive request patterns are screened out before they touch your application.
  • Network firewalls — host- and network-level rules limit which ports and services are reachable, with everything else closed by default.

Backups & recovery

We take daily backups of every site and keep them for 30 days, so a bad plugin update, a fat-fingered edit, or a worst-case incident is something you can roll back from rather than rebuild around.

  • Daily, automatic— backups run on their own; you don't have to remember to trigger them.
  • 30-day retention — you can reach back through a month of restore points.
  • One-click restore — recovery is a single action from your dashboard, not a support ticket and a long wait.
  • Encrypted storage — backups are encrypted at rest, just like your live data.

Access control

We treat access to your data as something to be earned and audited, not assumed. Internal access follows the principle of least privilege — people and systems get only the access they genuinely need, and no more.

  • Least privilege— permissions are scoped tightly and reviewed, so a single account can't reach everything.
  • Audited admin access— privileged actions on our infrastructure are logged, so there's a record of who did what and when.
  • Strong authentication — administrative access requires strong credentials and multi-factor authentication.
  • Brokered actions — your dashboard never talks to a hosting node directly; every infrastructure action is checked for ownership before it runs.

Monitoring & patching

We watch the platform around the clock and keep it current. Our nodes are monitored 24/7for health, availability, and unusual activity, and security updates are applied promptly so you're not left running known-vulnerable software.

  • 24/7 monitoring — automated systems and our team keep an eye on the fleet day and night.
  • Automatic security patches — operating-system and platform-level security updates are applied on a regular cadence.
  • Anomaly awareness — unusual traffic and resource patterns are flagged so we can act early.

Responsible disclosure

If you believe you've found a security vulnerability in CloudPerch, we want to hear from you. Please email security@cloudperch.io with enough detail for us to reproduce and verify the issue. We read every report and will work with you to confirm and resolve it.

We support good-faith research. If you make a sincere effort to follow these guidelines, we won't pursue or support legal action against you for your research:

  • Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly.
  • Don't access, modify, or delete data that isn't yours, and don't degrade the experience for other customers.
  • Avoid privacy violations, denial-of-service testing against production, spam, and social-engineering of our staff or customers.
  • Only interact with accounts you own or have explicit permission to test.

Acting in good faith under this policy is considered authorised, and we'll do our best to respond quickly and keep you updated.

Incident response

Even on a well-run platform, things can go wrong — and when they do, how we respond matters as much as how we prevent. We have a plan for containing, investigating, and recovering from security incidents, and our priority is always to protect customer data and restore service quickly.

  • Contain, then fix — we work to limit the blast radius first, then remove the root cause and restore from clean backups where needed.
  • Honest communication— if an incident materially affects you, we'll tell you what happened, what we did, and what you should do.
  • Live updates — during platform-wide events, our status pageis the fastest place to see what's happening and track recovery.

Our commitments

These are the security practices we hold ourselves to. We describe them as ongoing commitments rather than badges — security is work that's never finished, and we'd rather earn your trust by how we operate than by a logo on a page.

  • Keep customer sites isolated from one another by default.
  • Encrypt your data in transit and at rest.
  • Back up every site daily and make recovery a one-click action.
  • Apply security patches promptly and monitor the platform continuously.
  • Grant internal access on a least-privilege basis and audit privileged actions.
  • Collect only the data we need, and be clear about how we use it.
  • Respond honestly and quickly when something goes wrong.

To understand what data we hold and how we handle it, see our Privacy Policy, the Cookies page, and our Terms.

Contact

Security questions, concerns, or vulnerability reports are always welcome. The fastest way to reach our security team is security@cloudperch.io.

For suspected abuse of a site we host, email abuse@cloudperch.io. For anything else, you can reach us at hello@cloudperch.io or from the contact page.

Questions about this policy? Email hello@cloudperch.io or reach our team from the contact page.

CloudPerch.io

Your high ground in the cloud. Fast, dependable hosting with a genuinely human touch.

Product
Web hostingWeb supportDomainsServer hosting (soon)PricingStatus
Resources
How it worksFAQDocsBlog
Company
AboutCareersContactTrust & safety
© 2026 CloudPerch, Inc. · All systems nominal
PrivacyTermsSecurityCookies