Security

Security that starts before trouble does.

No silver bullets and no scare tactics: locked-down defaults, a clean recovery path through backups, and engineers who pick up when something looks wrong. Already hacked? Jump to the recovery path below, or talk to an engineer now.

On every plan

The defaults do the heavy lifting.

Free SSL everywhere

Let’s Encrypt certificates issued and renewed automatically, with force-HTTPS a single toggle away.

Auto-issue · auto-renew

HTTP basic-auth

Protect any path with a per-path username and password: wp-admin, client previews, members areas.

Per-path protection

Activity log

Every account action recorded: who did what, where, and when. When something changes, you can see it.

Full audit trail

Daily + on-demand backups

Automated daily backups plus snapshots before anything risky: your recovery path when something goes wrong.

One-click restore

Real logs

PHP errors and access logs through Elasticsearch and Kibana. See what actually happened, with data.

Elasticsearch · Kibana

Team permissions

Granular, per-action permissions across roles and organizations: fewer people with more access than they need.

Per-action control

Hacked? Here is what happens next

The recovery path, step by step.

  • Step 1 1
    Stop and assess

    Don’t delete anything yet. Note what looks wrong: defaced pages, strange redirects, admin users you don’t recognise.

  • Step 2 2
    Restore a clean backup

    Pick a backup from before the incident and restore it in one click. Daily and on-demand backups exist for every site.

  • Step 3 3
    Rotate credentials

    Change your WordPress, SSH/SFTP and database passwords, and remove any users that shouldn’t be there.

  • Step 4 4
    Update and close the gap

    Update WordPress, themes and plugins. Most incidents start with something outdated.

  • Step 5 5
    Talk to an engineer

    Contact us and an engineer goes through the logs with you to understand what happened and what to change.

Questions

Straight answers about hacked sites.

My site is hacked. What should I do right now?

If you host on Celestio: restore the most recent clean backup (it takes one click), then rotate your passwords, update everything, and contact us. An engineer will go through the logs with you.

Do you scan my site for malware?

No. We don’t offer malware scanning or a cleanup service today, and we won’t pretend otherwise. What you get is a locked-down platform, full backups as a recovery path, and engineers who help you investigate.

How do backups help against a hack?

Backups run automatically every day, and you can snapshot on demand before risky changes. A restore takes one click and puts the site back exactly as it was. That’s the fastest honest way out of most incidents.

I’m hosted elsewhere. Can you help?

Our tooling works on Celestio infrastructure, so the honest answer is: migrate in. Migration is assisted by an engineer on every plan, and the security defaults apply from day one.

Talk to a human

Site compromised? Talk to an engineer.

If your site is hosted with us, recovery usually means restoring a clean backup. Your details stay in Sweden.

Before, not after

The cheapest incident is the one that never happens.

Cleanup on its own is temporary. On managed hosting we clean the site and keep it clean: managed updates that close the gap, daily backups and monitoring, so the same problem does not come back. Move your site before you ever need this page.