Our autoscaling servers are up and running 99.9% of the time to ensure no downtimes
Skip links

Secure Hosting

Enterprise level website security built-in

In the digital landscape of today, the constant risks of security breaches and malware exposure pose a significant threat. Our reliable, secure hosting ensures your protection against malicious web attacks. We provide you with efficient tools to safeguard your time, finances, and reputation—all without imposing additional charges.

Stay one step ahead of online threats with Obvi8, included at no extra cost.

Home / Secure Hosting

Free and On-Demand

Automatic Malware Scanning

We scan all websites every day for common malware. Using commercial tools and systems developed in-house, we discover all sorts of nasties. Malware – such as web shells or mail/spam daemons – can compromise your installation, giving criminals access to your site’s data, email and content.

We give you a detailed report on the results of this scan in our control panel. This is similar to services provided by some other web hosts – which they charge a premium for!

Should malware be discovered, we can send you an email alert.

WordPress users also have another way to check for malware, through our WordPress Checksum Report in our WordPress Tools suite. This checks that your WordPress core matches the official WordPress repository.

malware-scan

Immediate results

If you’ve detected malware on your website, take the necessary steps to update your software or plugins and eliminate any compromised files. After implementing these changes, perform a prompt re-scan. You’ll receive immediate confirmation on the effectiveness of your fixes.

On-demand scanning

Our malware scanning stands out because it allows you to run the scanner whenever you need it, offering the convenience of on-demand functionality. This feature eliminates the need to wait for the next scheduled scan, providing flexibility in ensuring your website’s security.

Disables PHP Mail

If malware is identified, we take action by disabling PHP mail to prevent your website from spreading infections through email. This prompt action helps contain the potential harm and protects other users. Rest assured, we prioritize your site’s security and the well-being of your users.

wildcard-ssl-encryption

HTTPS EVERYWHERE

Free wildcard SSL encryption

SSL-TLS certificates play a crucial role in ensuring secure web browsing and data transfer. With legal requirements and Google’s endorsement emphasizing their importance, we collaborate with Let’s Encrypt to ensure that every site hosted by us becomes an ‘https’ site.

Our complimentary SSLs are ‘wildcard’ certificates, enabling you to secure both subdomains and your primary domain with a single certificate. To obtain a free ‘https’ certificate, your site must utilize the validated Obvi8 nameservers, offering the same high level of security as any other SSL certificate.

Email Scans

Anti-spam, anti-virus

All emails and forwarders sent and received are subject to advanced antivirus and anti-spam protection.

We use 3 layers of inbound spam and virus scanning:

Network-level

Commercial anti-spam deny lists from Spamhaus, Invaluement and Barracuda Networks are used to reject mail from known spam networks.

Virus Scanning

Any known malware signatures are rejected.

Content-based

Messages are scanned for spam-like characteristics and filtered into the ā€˜junk mail’ folder.

email-scans

Fully configurable email filters

These filters are fully configurable via the webmail control panel. So certain senders, domains and TLDs can be allow-listed to bypass the content filter entirely. The same goes with deny lists: you can create your own from our control panel.

Whenever we reject a message for a known virus or network deny listing, the message is returned to the sender so the sender knows what’s happening. We never ā€˜black hole’ email.

Spammers not welcome

If you utilize the email accounts provided with our web hosting, it’s crucial to prevent any malicious activity that could harm both your reputation and ours, especially through the distribution of mass ‘spam’ emails.

To safeguard against this, we actively monitor outgoing emails and strictly enforce a zero-tolerance spam policy, ensuring a secure and reputable email environment for our users.

TWO-FACTOR AUTHENTICATION

Safer than just a password

Unfortunately, many security measures are rendered ineffective if your password is compromised. So we offer the option to use two-factor authentication (2FA) for the Control Panel and SSH access.

2FA is a way to add an extra layer of security. Our 2FA uses TOTP apps, which provide you with a time-sensitive single-use code to enter as well as your password. 2FA app providers include Google and Microsoft. The apps are run from your phone.

We also enforce another form of ā€˜2FA’: random security checks when payments are made. This will require you to call us and confirm additional security information provided by yourself when first signing up.

two-factor
anti-ddos

1 TBPS+ ANTI-DDOS

Enterprise-level denial of service protection

Distributed denial of service (DDoS) attacks are a growing hazard on the web. They can do extensive damage to a business by flooding the server with requests, so that regular website users are unable to access your website.

If your shared hosting or virtual private server (VPS) is attacked, usually you don’t have much of a choice other than to weather the storm and wait for the attack to stop.

That’s why we introduced 1 Tbps+ anti-DDoS protection. This enterprise-level protection covers you against most attacks. It only filters-out malicious traffic, so you can carry on working without noticing any interruption. Don’t let the hackers ruin your business.

WEB APPLICATION FIREWALL

Strong external protections

To thwart security breaches, it’s crucial to prevent unauthorized access to your server’s code. Our Web Application Firewall (WAF) acts as a protective barrier, blocking suspicious activities and ensuring the security of your data and software.

Web forms are susceptible to attacks, with criminals attempting to insert malicious code. Traditional firewalls often fall short in protecting forms, as they must permit the flow of information between users and the hosting server. This vulnerability can serve as an entry point for data theft or ransomware, posing a significant threat to businesses in terms of time and financial costs.

Our integrated WAF serves as a proactive defense, scrutinizing every HTTP request for various types of attacks, such as SQL injection, trojans, cross-site scripting, and path traversal. Positioned at the edge of our network, it intervenes before scripts from web apps, like WordPress, execute—ensuring a rapid response in less than a millisecond.

firewall

INFRASTRUCTURE THAT’S UNMATCHED FOR RESILIENCE

The best platform for security

The unique ways we set up our servers makes huge differences.

Autoscaling

A cyber-attack uses up a lot of web hosting resources, even if it’s unsuccessful. If you’re on our shared hosting, our autoscaling servers will account for the attack, meaning that your site will stay fast and online. At other hosts, an attack on one of your hosting ā€˜neighbours’ can slow down your site. Not so at Obvi8.

No single point of failure

Our platform incorporates redundancy at all levels, ensuring resilience in the face of hardware, software, or network failures. In the event of any such failure, an automatic failover mechanism swiftly restores services, enhancing availability and minimizing the risk of data loss. This redundant hardware and software design serves as a robust safeguard for uninterrupted and secure operations.

Isolated server roles

Our web servers exclusively handle websites, MySQL servers are dedicated to running MySQL, and email servers focus solely on managing emails. Central log servers receive logs from these isolated server roles. This segregation ensures that even in a worst-case scenario where a website is compromised, attackers cannot obscure their tracks or access email content.

Explore
🔰 🔲