Security and Backups, Described Precisely Enough to Hold Us To
We've cleaned up too many hacked sites on other hosts to be vague about this. Here is what protects your site, where your backups are, and what happens when something gets through anyway.
- Same price on renewal
- Daily off-server backups
- Free cPanel migration
- Support in IST hours
Why this page is specific
Before Techpullers Cloud existed, the most common emergency our agency handled was a client's site compromised on someone else's hosting, malware in the theme, spam pages in Google, a blacklisted domain, and a host whose answer was "restore from your backup," which turned out to live on the same failed server. That experience shaped every line below.
Shared and Managed WordPress (France)
Imunify360 on every plan. Real-time malware scanning of files as they're written, a web application firewall that blocks exploit attempts before they reach PHP, brute-force protection on cPanel, WordPress and email logins, and automatic cleanup of infected files with a report to you. It runs on Launch, not just on the expensive tiers, because a ₹299 site gets attacked exactly as often as a ₹1,499 one.
CloudLinux account isolation. Each account runs in its own lightweight container with fixed CPU, RAM and process limits (LVE) and a virtual filesystem (CageFS). One compromised account cannot read another's files or exhaust the server.
Hardened PHP. Per-account PHP versions with dangerous functions disabled by default, and PHP-FPM under LiteSpeed. Old PHP versions are retired on a schedule; we'll warn you before yours is.
Free SSL, always renewed. Let's Encrypt certificates via cPanel AutoSSL for every domain and subdomain, renewed automatically. HTTPS redirects on request. Expired-certificate warnings are our failure, not yours.
Email protection. SPF, DKIM and DMARC records created for every hosted domain; outbound rate limiting so one hijacked mailbox can't get the server blacklisted; spam filtering inbound.
WordPress hardening (Managed WordPress plans). File editing disabled in wp-admin, XML-RPC restricted, login rate-limited, security headers set, file permissions locked, and plugins with known unpatched vulnerabilities flagged at our weekly update run.
Cloud, Managed Cloud and Dedicated
Network-edge DDoS mitigation on all cloud locations, included.
On managed plans, we install and maintain: a host firewall with only required ports open, SSH hardened to key-only authentication on a non-default port, fail2ban, automatic security updates, malware scanning (Imunify or equivalent) and, where a control panel is present, its own hardening profile. On unmanaged Cloud VPS, security above the hypervisor is yours; our VPS security checklist is the same one we use.
Backups, the part most hosts get wrong
Where they are. Every backup is written to an off-server storage box in Falkenstein or Helsinki. Shared and WordPress servers are in France; cloud servers are in our German, Finnish, Singapore and US facilities. In every case the backup is in a different data centre from the server, and for shared hosting it's with a different company entirely. A server failure, a data-centre incident or an account compromise cannot take the backups with it.
How often, and how long we keep them.
| Plan | Frequency | Retention | Restore |
|---|---|---|---|
| cPanel Launch / WP Launch | Daily | 14 days | By ticket |
| cPanel Grow / WP Grow | Daily + on-demand | 30 days | Self-service in cPanel, or ticket |
| cPanel Scale / WP Scale | Daily + on-demand | 60 days | Self-service, or ticket |
| Managed Cloud | Nightly | 14–30 days (plan) | By ticket |
| Managed Dedicated | Nightly | 30 days | By ticket |
| Cloud VPS (unmanaged) | Add-on you enable | 7 snapshots | Self-service |
What's in them. Full cPanel account backups: files, databases, email, DNS zones, settings. On managed servers: full system or application-level backups depending on setup, agreed with you.
We test restores. A backup that has never been restored is a hope, not a backup. We restore a sample account from the off-server backup storage monthly and log it.
When something gets through
No system is perfect, and WordPress sites with weak plugins are attacked constantly. If a site on a managed or shared plan is compromised:
- We isolate it (Imunify360 quarantines infected files automatically; on cloud plans we take the affected vhost offline if needed).
- We clean it (remove injected code, backdoors and rogue admin users) and identify the entry point.
- We close the entry point: update or remove the vulnerable plugin, reset credentials, tighten permissions.
- We restore from a clean backup if cleanup isn't safe, and tell you which date we went back to.
- We check Google Search Console and blacklists and request review where needed.
- You get a short written report: what happened, how, what we changed.
Malware cleanup is included on all shared, WordPress, managed cloud and managed dedicated plans. It is not billable, and it is not "please contact your developer."
Your part
Security is shared. The things that most often let attackers in on client sites we've cleaned:
- Nulled or abandoned plugins and themes
- Admin usernames of "admin" with reused passwords
- Sites that hadn't been updated in a year
- FTP credentials emailed around the office
Use a password manager, keep updates on (or let us do them), and don't install plugins from unofficial sources. Ask us before installing something you're unsure about; we'll check it.
Access and credentials
Migration credentials you give us are stored in an encrypted vault and deleted when the job's done. Techpullers staff access to your account is logged. We don't share server access with third parties, and we'll never ask for your password by email or WhatsApp, only through the client portal.
Frequently asked questions
Is Imunify360 on the cheapest plan?
Yes, on Launch.
Are backups included or an add-on?
Included on all shared, WordPress, managed cloud and managed dedicated plans. On unmanaged Cloud VPS they're an add-on you enable.
Can I download my backups?
Yes, from cPanel, or by ticket on managed servers.
Do you offer DDoS protection?
At the network edge, yes, on every plan, at every location.
Is there a WAF?
Yes, Imunify360's WAF on shared/WordPress; a firewall plus scanning on managed servers.
What about Cloudflare?
Not bundled. Cloudflare's free plan adds another layer and we'll help you set it up.
Talk to an engineer about your site
GST invoice on every payment. Same price on renewal.