Every page is served over HTTPS and enforced with HSTS (1 year, including subdomains) — your browser refuses to connect any other way, on every visit.
Third-party API calls are proxied server-side, so access tokens are never visible in a browser's network requests. Stored secrets are encrypted at rest, never displayed in plain text.
Backups run on a regular automated schedule to independent cloud storage, kept separate from the production server itself.
Public-facing endpoints are rate-limited to block automated abuse and scraping, without adding friction for real users.
Personal information is stripped from internal logs and error reports before they're written — logs exist to fix problems, not to store customer data.
Legacy WordPress attack surfaces — XML-RPC, the REST API's public user directory, in-dashboard file editing — are disabled or restricted at the server level.
If you need more detail for a vendor review or procurement checklist, we're happy to walk through it directly.
Contact us