Security you can check,
not just claims.

Every site runs walled off from every other, behind a managed firewall, on servers that never leave the EU. Below is what that actually means — and where we have tested it rather than assumed it.

We attacked it ourselves

“Isolated” is the easiest word in hosting to write and the hardest to prove. So we tried to break it on purpose, on real infrastructure, and measured what happened to the site next door.

We pinned one site’s CPU to 100%

Then we measured the site sharing its machine. The difference was within measurement noise — and the site on a completely different machine actually fared slightly worse. Your processing power is yours; a neighbour cannot take it.

We drove one site out of memory

The runaway process was killed at that site’s own limit. Its neighbour never dropped a request and the machine’s memory never moved. One site cannot exhaust the server underneath everyone else.

Nothing can reach across

Each site has its own database and its own network rules that block it from reaching any other site on the platform. A compromise stays in the environment it started in.

We also shut a server down mid-request, took a machine offline, and stopped a database in the middle of a checkout — that story is on the reliability page.

What runs in front of, and around, your site

Security is not one product. These run on every site, on every plan, with nothing to switch on and nothing to pay extra for.

Managed firewall

A web application firewall runs in front of every site, blocking known exploits, common attack patterns and scanner traffic before any of it reaches WordPress. It is on by default — there is no security tier to upgrade to.

Malware scanning

Every site is scanned each night, and again immediately whenever a file is uploaded or a plugin is installed — the two moments something usually arrives. Findings raise an alert and appear in your dashboard.

Login protection

Repeated failed logins are detected and the source is blocked automatically, with every attempt — address, username, time and outcome — kept in a login history you can read. You can also move your login page to an address bots do not know.

Runtime detection

A kernel-level agent watches process behaviour inside every container in real time. If something starts behaving like an intrusion rather than like WordPress, we are alerted immediately.

Host monitoring

Every server underneath the platform runs host intrusion detection, file-integrity monitoring, vulnerability detection and CIS benchmark checks — so we see a problem on the machine, not only in the container.

Image scanning

The container images your site runs on are scanned continuously for known vulnerabilities, and rebuilt from a clean base rather than patched in place. Nothing an attacker leaves behind survives a restart.

In the EU, and encrypted

Your site, your files, your database and your backups never leave the European Union. Servers in Germany and Finland; backups written to EU-jurisdiction storage that cannot be replicated outside the region.

Encrypted at rest

Every credential and key the platform holds is encrypted in storage rather than sitting in plain text, and none of them live in readable form in our source code.

Encrypted in transit

Every site gets a certificate that provisions and renews itself. HTTPS is on from the moment you go live, with nothing to configure and no renewal to forget.

Named sub-processors

Every company that touches your data is listed in our Data Processing Agreement, with where it sits and on what legal basis. Where a provider is incorporated outside the EU, the data still stays in an EU region.

Backups that are actually tested

A backup nobody has ever restored is a hope, not a backup. Ours are written nightly to storage completely separate from the server your site runs on, kept for 30 days, and restored with one click.

We restore them on purpose

We take a real backup, restore it into an isolated environment, and check the recovered site against the live one — tables, settings and actual posts, not just file sizes. The last drill matched exactly.

Databases fail over on their own

Your database runs with live standby copies. We have stopped the primary mid-transaction under load: writes paused for seconds, nothing was lost, and visitors kept reading the site throughout.

You can see who did what

Account actions are recorded in an append-only activity log, and your dashboard login can be protected with two-factor authentication.

Security, answered

Has any of this been independently tested?Έχει ελεγχθεί ανεξάρτητα κάτι από αυτά;

Honestly: partly. We run our own adversarial testing — we deliberately attack our platform and publish what happened, including the isolation results on this page and the failure testing on our reliability page. What we have not yet had is a third-party penetration test of Grandhosting, and we would rather say so than imply otherwise. When we commission one, we will say that too.

Ειλικρινά: εν μέρει. Κάνουμε δικές μας επιθετικές δοκιμές — επιτιθέμεθα σκόπιμα στην πλατφόρμα μας και δημοσιεύουμε τι συνέβη, μαζί με τα αποτελέσματα απομόνωσης σε αυτή τη σελίδα και τις δοκιμές αστοχίας στη σελίδα αξιοπιστίας. Αυτό που δεν έχουμε ακόμη είναι έλεγχος διείσδυσης (penetration test) από τρίτο φορέα για το Grandhosting, και προτιμούμε να το πούμε παρά να υπονοήσουμε το αντίθετο. Όταν τον αναθέσουμε, θα το πούμε επίσης.

What happens if another site on the platform gets hacked?Τι γίνεται αν χακαριστεί ένα άλλο site στην πλατφόρμα;

Nothing reaches you. Each site runs in its own isolated environment with its own database, and network rules stop one site from reaching another at all. That is the failure that takes down whole shared servers elsewhere, and it is the specific thing this architecture exists to prevent.

Δεν σας αγγίζει τίποτα. Κάθε site τρέχει στο δικό του απομονωμένο περιβάλλον με τη δική του βάση δεδομένων, και οι κανόνες δικτύου εμποδίζουν εντελώς ένα site να φτάσει σε άλλο. Αυτή ακριβώς η αστοχία ρίχνει ολόκληρους κοινόχρηστους servers αλλού, και είναι το συγκεκριμένο πράγμα που αυτή η αρχιτεκτονική υπάρχει για να αποτρέψει.

Where is my data actually stored?Πού αποθηκεύονται πραγματικά τα δεδομένα μου;

In the European Union, and it does not leave. Your site and database run on servers in Germany and Finland, and backups are written to EU-jurisdiction storage that cannot be replicated outside the region. Some of the companies behind that infrastructure are incorporated in the United States — every one is named in our Data Processing Agreement, with the data kept in an EU region under Standard Contractual Clauses.

Στην Ευρωπαϊκή Ένωση, και δεν φεύγει από εκεί. Το site και η βάση δεδομένων σας τρέχουν σε servers σε Γερμανία και Φινλανδία, και τα αντίγραφα ασφαλείας γράφονται σε αποθηκευτικό χώρο δικαιοδοσίας ΕΕ που δεν μπορεί να αναπαραχθεί εκτός της περιοχής. Ορισμένες από τις εταιρείες πίσω από αυτή την υποδομή εδρεύουν στις ΗΠΑ — όλες κατονομάζονται στη Σύμβαση Επεξεργασίας Δεδομένων μας, με τα δεδομένα να παραμένουν σε περιοχή ΕΕ υπό Τυποποιημένες Συμβατικές Ρήτρες.

Can I see what the firewall blocked on my site?Μπορώ να δω τι μπλόκαρε το firewall στο site μου;

Yes — and you can act on it yourself. Your dashboard lists each blocked request with the rule that triggered it, so if a legitimate action of yours was caught you can lift that specific rule with one click instead of opening a ticket and waiting.

Ναι — και μπορείτε να ενεργήσετε μόνοι σας. Το dashboard σας εμφανίζει κάθε μπλοκαρισμένο αίτημα μαζί με τον κανόνα που το ενεργοποίησε, οπότε αν μια νόμιμη ενέργειά σας παγιδεύτηκε, μπορείτε να άρετε τον συγκεκριμένο κανόνα με ένα κλικ αντί να ανοίξετε αίτημα υποστήριξης και να περιμένετε.

What if I need to get an old version of my site back?Τι γίνεται αν χρειαστεί να επαναφέρω μια παλιά έκδοση του site μου;

Every site is backed up nightly to storage that is entirely separate from the server it runs on, kept for 30 days, and restored with one click. We also test that those backups actually restore — not just that the files exist, but that the recovered site matches the live one, content included.

Κάθε site λαμβάνει νυχτερινό αντίγραφο ασφαλείας σε αποθηκευτικό χώρο εντελώς ξεχωριστό από τον server όπου τρέχει, διατηρείται για 30 ημέρες και επαναφέρεται με ένα κλικ. Επίσης ελέγχουμε ότι αυτά τα αντίγραφα όντως επαναφέρονται — όχι απλώς ότι τα αρχεία υπάρχουν, αλλά ότι το ανακτημένο site ταιριάζει με το ζωντανό, μαζί με το περιεχόμενο.

Founding Member pricing.
Yours forever.

From €3.49/mo — pay only for the compute you use. Every feature included. Founding-member prices lock forever — they only increase at public launch.

Early access means direct access to our team. You’re not a ticket number. You’re a founding partner.

Free during the beta. No commitment, no card. Takes a minute.

Apply for Founding Access →

Already hosted elsewhere? Managed migration, zero downtime →