Always on.
And honest about it.

Your website is your business. Here’s exactly how we keep it online and your data safe — the redundancy, the backups, and what actually happens when something goes wrong. No buzzwords, no fine print.

Built so one failure isn’t your failure

Traditional hosting puts your site on a single server. If that server has a bad day, so does your site. We designed the platform the opposite way: every layer has a backup, and most failures are handled automatically.

A note on sizing: the features that need more than one machine — running on multiple live servers and auto-scaling — come with the Standard tier (from €5.99/mo + VAT). The Micro tier runs a site on a single instance from €3.49/mo + VAT, ideal for brochure and landing-page sites. You choose the tier for each site and can switch any time.

No single server to fail

On Standard (from €5.99/mo + VAT), your site runs on more than one server at once behind a load balancer — so if one fails, the others keep serving visitors while a replacement starts automatically, with nothing for you to do.

Dedicated database with failover

Your site has its own database on our high-availability cluster — never a shared database server. The cluster keeps live copies on separate machines, and if the main one fails a standby is promoted automatically, with no action from you. In our tests that took about 14 seconds, with no lost writes.

A redundant control plane

It isn't only your servers that have a backup — the platform that orchestrates and heals them runs on multiple machines too. There's no single brain whose failure could stop everything, so the system keeps making the right decisions even if part of it goes down.

Servers that heal themselves

Every instance is health-checked constantly. If one stops responding or starts misbehaving, it's automatically taken out of rotation and replaced with a fresh, healthy one — traffic is only ever sent to servers that are passing their checks.

Spikes add capacity, not downtime

On Standard, when traffic climbs, your site adds more servers automatically, then scales back down when it settles. A sudden rush — a campaign, a viral post, a sale — means more capacity, not a crash. You only pay for what you actually use.

Isolated from every other site

Your site runs in its own isolated environment, walled off at the network and resource level. Another customer's traffic surge, runaway plugin, or security incident can never spill over and affect you. No noisy neighbors, no shared fate.

Zero-downtime updates

Updates roll out by starting fresh servers on the new version, waiting for them to pass health checks, then retiring the old ones. Your visitors are always served by a healthy server — there is no maintenance window and no "be right back" page.

HTTPS that never lapses

Every site gets a free SSL certificate that's provisioned and renewed automatically. You'll never get a surprise "this certificate has expired" outage — keeping your padlock and your visitors' trust intact takes nothing from you.

Watched around the clock

Every site is probed continuously and key infrastructure is monitored automatically. If something looks wrong, our team is alerted immediately — and several classes of failure are detected and recovered without anyone having to wake up.

Your content, protected and consistent

Staying online is only half of it. Your data also has to be safe, recoverable, and identical on every server running your site. Here is how we make sure of that.

Daily backups, one-click restore

Your database and files are backed up every night and kept on secure, independent EU storage — separate from the servers your site runs on, so your backups survive even a total failure of the live infrastructure. 30-day retention as standard, restore in one click, and a 20-year permanent option for records you must keep.

Durable media storage

Your uploads — images, PDFs, downloads — don't sit on one server's disk. They live on resilient, replicated object storage and are served straight from it, not from your web server. A server failure never loses your media. An optional CDN can be switched on per site.

Clean boot, every time

WordPress core and the server software are baked into a verified, read-only image, and every server starts from that same image. WordPress itself restarts from a clean, read-only copy, so tampered core files don't survive; plugins, themes and uploads are scanned for malware every night.

Consistent across every server

On Standard your site runs on several servers, so we make sure they always agree. When you install a plugin, change a theme, or run an update, the change is applied once and propagates to every server within seconds — you never get one version on one server and a different one on another.

You choose the balance, per site

Each site can pick how it balances speed against strict consistency — one click in the dashboard. Most sites run on Balanced. A checkout or membership site can switch to Strict, so every server always reads the very latest data. The choice is yours, and it is set per site.

What actually happens during a failure

Every host promises “reliability.” Fewer will tell you what happens at the exact moment something breaks. Here’s the honest version.

A web server fails

The load balancer simply stops sending traffic to the failed server and a replacement starts automatically. On Standard your site is already running on more than one server, so visitors keep browsing without noticing.

The database server fails

A standby copy of your database is promoted automatically and your site reconnects on its own. In our tests that took about 14 seconds, with no lost writes. Because the standby is kept continuously up to date, at most a fraction of a second of the very latest writes is at risk on a hard crash — everything else is already safely replicated.

An update goes out

New servers start on the new version and have to pass health checks before they receive any traffic. The old servers are only retired once the new ones are proven healthy. If the new version misbehaves, we roll back to the previous one. You see no downtime either way.

Something corrupts your data

A bad import, a buggy plugin, or a mistaken edit can damage content on any platform. Every site has a nightly backup kept for 30 days, and you restore any of them from your dashboard in one click.

Being straight with you: no host can promise literally zero downtime or zero data loss — anyone who does is selling you something. What we promise is that failures are designed for, recovered automatically wherever possible, and measured in seconds rather than hours. We back a 99.9% uptime SLA.

We don’t just design for failure. We cause it.

Most hosts tell you they’re reliable. We’d rather show you. Under simulated load, in our tests, we deliberately break things — and measure what a visitor would actually see.

We killed a running server mid-request

Not a graceful shutdown — we pulled it mid-request, the worst case, while the site served dozens of simulated visitors at once. The site stayed up on its other copy. One request hung briefly; everything else kept loading.

We took a whole machine offline

The site’s server was drained out from under it. The site moved to a healthy machine in seconds. A probe checking the site every second saw no failures at all.

We shut down the database mid-checkout

This is the one that matters most. When your database changes hands, the risk isn’t a down page — it’s a half-finished order. We shut down the main database while a stream of orders was being written. A standby took over on its own; writes paused for a few seconds, then resumed — and when we checked the data afterward, not one confirmed order was lost.

That last one is why we can say “recovery in seconds” without crossing our fingers. We’ve watched it happen — on purpose, more than once.

The short version

Everything on this page is live today — not a roadmap. Here it is in one table.

CapabilityWhat it means for youStatus
Multi-server redundancyOn Standard, your site runs on more than one server at once, so no single machine can take it down.Live
Automatic database failoverA standby database takes over on its own if the main one fails — about 14 seconds with no lost writes, in our tests.Live
Redundant control planeThe platform that orchestrates and heals your servers runs on multiple machines — no single point of control.Live
Self-healing & auto-scalingUnhealthy servers are replaced automatically; on Standard, traffic spikes add capacity instead of causing downtime.Live
Site isolationEach site runs walled off from every other — a neighbor’s spike or compromise can’t affect you.Live
Off-site backups & one-click restoreNightly backups on independent storage, separate from your live site; 30-day retention (20-year option), one-click restore.Live
Durable media storageUploads live on replicated object storage and are served straight from it — never lost with a server.Live
Cross-server consistencyPlugin, theme, and update changes apply once and reach every server in seconds.Live
Per-site consistency controlChoose Balanced, Strict, or single-instance per site, in one click.Live
Zero-downtime updatesNew versions roll out behind health checks — no maintenance window.Live
Continuous monitoringEvery site is probed around the clock; failures alert us immediately.Live
EU data residencyStored and backed up entirely within ISO 27001-certified EU data centers.Live

Multi-server redundancy and auto-scaling come with the Standard tier (from €5.99/mo + VAT); the Micro tier runs a single instance from €3.49/mo + VAT. You choose, and can switch any time.

Reliability, in plain language

If a server goes down, does my site go down?

Busier sites run across more than one server at the same time, so if one fails the others keep serving visitors without a blip. A low-traffic site on a single instance (Micro) can see a brief interruption while a replacement starts — which is why any site where downtime costs you money belongs on Standard, which runs on multiple auto-scaling instances from €5.99/mo + VAT. You choose the tier for each site and can switch any time.

Can I lose my data?

We’re built to make that extremely unlikely. Your database is kept live on more than one machine at once and backed up every night, with each backup kept for 30 days. In the worst case — a hard crash of the main database server — at most a fraction of a second of the very latest writes is at risk, because everything else is already replicated. We won’t claim it’s impossible to ever lose anything — no honest host can — but realistically your data is safe.

What happens to my site when you push an update?

Nothing visible. Updates roll out by starting fresh servers on the new version, checking they’re healthy, and only then retiring the old ones. There’s no maintenance window and no “be right back” page. If a new version ever misbehaves, we roll back to the previous one.

My site runs on several servers — won't they get out of sync?

No, and this is something we put real engineering into. When you install a plugin, switch a theme, or run an update, the change is applied once and propagates to every server within seconds. You’ll never get one version of your site on one server and a different one on another. For checkout, membership, or other sites where it matters most, you can switch that site to Strict mode in one click, which guarantees every server always reads the very latest data.

What's a realistic recovery time if something breaks?

For an automatic database failover, about 14 seconds with no lost writes in our tests, with no action from you. For a failed web server, effectively no interruption — another server keeps serving while a replacement starts. For a full restore from backup, minutes — one click from your dashboard. We back a 99.9% uptime SLA.

Where is my data stored?

Entirely within the European Union. Your site, your database, and your backups all live in ISO 27001-certified EU data centers. Nothing is stored or backed up outside the EU, which keeps you straightforwardly GDPR-compliant. See our GDPR page and DPA for the details.

Do I have to manage any of this?

No. Redundancy, failover, backups, monitoring, and update roll-outs all happen automatically — there’s nothing for you to configure or maintain. The one thing you can control, if you want to, is the per-site consistency mode (Balanced or Strict), and even that is a single click. Everything else is just on.

Founding Member pricing.
Yours while you stay.

From €3.49/mo + VAT — pay only for the compute you use. Founding-member pricing stays locked for as long as your account remains active.

Early access means direct access to our team. You’re not a ticket number. You’re a founding partner.

No commitment and no card to start. Takes a minute.

Create your account →

Already hosted elsewhere? Managed migration, zero downtime →