secure web hosting

Security and Backups, Described Precisely Enough to Hold Us To

We've cleaned up too many hacked sites on other hosts to be vague about this. Here is what protects your site, where your backups are, and what happens when something gets through anyway.

  • Same price on renewal
  • Daily off-server backups
  • Free cPanel migration
  • Support in IST hours

Why this page is specific

Before Techpullers Cloud existed, the most common emergency our agency handled was a client's site compromised on someone else's hosting, malware in the theme, spam pages in Google, a blacklisted domain, and a host whose answer was "restore from your backup," which turned out to live on the same failed server. That experience shaped every line below.

Shared and Managed WordPress (France)

Imunify360 on every plan. Real-time malware scanning of files as they're written, a web application firewall that blocks exploit attempts before they reach PHP, brute-force protection on cPanel, WordPress and email logins, and automatic cleanup of infected files with a report to you. It runs on Launch, not just on the expensive tiers, because a ₹299 site gets attacked exactly as often as a ₹1,499 one.

CloudLinux account isolation. Each account runs in its own lightweight container with fixed CPU, RAM and process limits (LVE) and a virtual filesystem (CageFS). One compromised account cannot read another's files or exhaust the server.

Hardened PHP. Per-account PHP versions with dangerous functions disabled by default, and PHP-FPM under LiteSpeed. Old PHP versions are retired on a schedule; we'll warn you before yours is.

Free SSL, always renewed. Let's Encrypt certificates via cPanel AutoSSL for every domain and subdomain, renewed automatically. HTTPS redirects on request. Expired-certificate warnings are our failure, not yours.

Email protection. SPF, DKIM and DMARC records created for every hosted domain; outbound rate limiting so one hijacked mailbox can't get the server blacklisted; spam filtering inbound.

WordPress hardening (Managed WordPress plans). File editing disabled in wp-admin, XML-RPC restricted, login rate-limited, security headers set, file permissions locked, and plugins with known unpatched vulnerabilities flagged at our weekly update run.

Cloud, Managed Cloud and Dedicated

Network-edge DDoS mitigation on all cloud locations, included.

On managed plans, we install and maintain: a host firewall with only required ports open, SSH hardened to key-only authentication on a non-default port, fail2ban, automatic security updates, malware scanning (Imunify or equivalent) and, where a control panel is present, its own hardening profile. On unmanaged Cloud VPS, security above the hypervisor is yours; our VPS security checklist is the same one we use.

Backups, the part most hosts get wrong

Where they are. Every backup is written to an off-server storage box in Falkenstein or Helsinki. Shared and WordPress servers are in France; cloud servers are in our German, Finnish, Singapore and US facilities. In every case the backup is in a different data centre from the server, and for shared hosting it's with a different company entirely. A server failure, a data-centre incident or an account compromise cannot take the backups with it.

How often, and how long we keep them.

Plan Frequency Retention Restore
cPanel Launch / WP Launch Daily 14 days By ticket
cPanel Grow / WP Grow Daily + on-demand 30 days Self-service in cPanel, or ticket
cPanel Scale / WP Scale Daily + on-demand 60 days Self-service, or ticket
Managed Cloud Nightly 14–30 days (plan) By ticket
Managed Dedicated Nightly 30 days By ticket
Cloud VPS (unmanaged) Add-on you enable 7 snapshots Self-service

What's in them. Full cPanel account backups: files, databases, email, DNS zones, settings. On managed servers: full system or application-level backups depending on setup, agreed with you.

We test restores. A backup that has never been restored is a hope, not a backup. We restore a sample account from the off-server backup storage monthly and log it.

When something gets through

No system is perfect, and WordPress sites with weak plugins are attacked constantly. If a site on a managed or shared plan is compromised:

  • We isolate it (Imunify360 quarantines infected files automatically; on cloud plans we take the affected vhost offline if needed).
  • We clean it (remove injected code, backdoors and rogue admin users) and identify the entry point.
  • We close the entry point: update or remove the vulnerable plugin, reset credentials, tighten permissions.
  • We restore from a clean backup if cleanup isn't safe, and tell you which date we went back to.
  • We check Google Search Console and blacklists and request review where needed.
  • You get a short written report: what happened, how, what we changed.

Malware cleanup is included on all shared, WordPress, managed cloud and managed dedicated plans. It is not billable, and it is not "please contact your developer."

Your part

Security is shared. The things that most often let attackers in on client sites we've cleaned:

  • Nulled or abandoned plugins and themes
  • Admin usernames of "admin" with reused passwords
  • Sites that hadn't been updated in a year
  • FTP credentials emailed around the office

Use a password manager, keep updates on (or let us do them), and don't install plugins from unofficial sources. Ask us before installing something you're unsure about; we'll check it.

Access and credentials

Migration credentials you give us are stored in an encrypted vault and deleted when the job's done. Techpullers staff access to your account is logged. We don't share server access with third parties, and we'll never ask for your password by email or WhatsApp, only through the client portal.

Questions

Frequently asked questions

Is Imunify360 on the cheapest plan?

Yes, on Launch.

Are backups included or an add-on?

Included on all shared, WordPress, managed cloud and managed dedicated plans. On unmanaged Cloud VPS they're an add-on you enable.

Can I download my backups?

Yes, from cPanel, or by ticket on managed servers.

Do you offer DDoS protection?

At the network edge, yes, on every plan, at every location.

Is there a WAF?

Yes, Imunify360's WAF on shared/WordPress; a firewall plus scanning on managed servers.

What about Cloudflare?

Not bundled. Cloudflare's free plan adds another layer and we'll help you set it up.

Get started

Talk to an engineer about your site

GST invoice on every payment. Same price on renewal.