Security you can check,
not just claims.

Every site runs sealed off from every other, behind a firewall that blocks hacking attempts, with malware scans every night, and your data never leaves the EU. Below is what that means for you — and where we have tested it rather than assumed it.

We attacked it ourselves

“Isolated” is the easiest word in hosting to write and the hardest to prove. So we tried to break it on purpose, on real infrastructure, and measured what happened to the site next door.

We pinned one site’s CPU to 100%

Then we measured the site sharing its machine. The difference was within measurement noise — and the site on a completely different machine actually fared slightly worse. Your processing power is yours; a neighbour cannot take it.

We drove one site out of memory

The runaway process was killed at that site’s own limit. Its neighbour never dropped a request and the machine’s memory never moved. One site cannot exhaust the server underneath everyone else.

Nothing can reach across

Each site has its own database and its own network rules that block it from reaching any other site on the platform. A compromise stays in the environment it started in.

We also shut a server down mid-request, took a machine offline, and stopped a database in the middle of a checkout — that story is on the reliability page.

What runs in front of, and around, your site

Security is not one product. These run on every site, on every plan, with nothing to switch on and nothing to pay extra for.

A firewall that blocks hacking attempts

A web application firewall runs in front of every site and blocks known exploits, common attacks and vulnerability scanners before they reach WordPress. Every blocked request is listed in your dashboard, and you can allow a false alarm with one click. It is on for every site: there is no security tier to upgrade to.

Malware scanning

Every site is scanned every night, and again whenever a plugin is installed, which is when something bad usually arrives. Findings raise an alert and appear in your dashboard.

Login protection

Repeated failed logins are blocked automatically, and every attempt (address, username, time and outcome) is kept in a login history you can read. You can also move your login page to an address bots do not know.

Intrusion detection

What runs in every site's environment is watched in real time. If something starts behaving like an intruder rather than like WordPress, we are alerted immediately.

Server monitoring

Every server underneath the platform is watched too: intrusion detection, alerts when important files change, and checks for known vulnerabilities and weak settings. So we see a problem on the machine, not only on the site.

A clean, protected WordPress core

The software your site runs on is checked continuously for known vulnerabilities and replaced with a clean, updated version rather than patched in place. WordPress core runs from a clean, protected copy, so a tampered core file doesn't survive a restart; plugins, themes and uploads are scanned for malware every night.

In the EU, and encrypted

Your site, your files, your database and your backups never leave the European Union. Hosted mainly in Germany, always within the EU, in ISO 27001-certified data centres; backups kept on separate storage in the EU.

Encrypted at rest

Every credential and key the platform holds is encrypted in its storage.

Encrypted in transit

Every site gets a certificate that provisions and renews itself. HTTPS is on from the moment you go live, with nothing to configure and no renewal to forget.

Named sub-processors

Every company that touches your data is listed in our Data Processing Agreement, with where it sits and on what legal basis. Where a provider is incorporated outside the EU, the data still stays in an EU region.

Backups that are actually tested

A backup nobody has ever restored is a hope, not a backup. Ours are written nightly to storage completely separate from the server your site runs on, kept for 30 days, and restored with one click.

We restore them on purpose

We take a real backup, restore it into an isolated environment, and check the recovered site against the live one — tables, settings and actual posts, not just file sizes. The last drill matched exactly.

Databases fail over on their own

A live copy of your database is kept on another server and takes over by itself. We have stopped the main database in the middle of orders under load: in our tests writes paused for about 14 seconds, nothing was lost, and visitors kept reading the site throughout.

You can see who did what

Account actions are recorded in an append-only activity log, and your dashboard login can be protected with two-factor authentication.

What if something happens to us?

You should never depend on any host, including us. So we make sure your site, your data and your domain are yours to take elsewhere.

Standard WordPress

Your site is standard WordPress, with nothing proprietary to untangle. Any WordPress host can run it.

Take a full backup and go

Your database and your files, in standard formats. No exit fee, no lock-in.

Your domain stays yours

A domain you register through us is registered in your name, so it goes wherever you go.

30 days to export

If you cancel, your website data (files and database) stays available for export for 30 days, as our Terms (section 10.2) set out.

Security, answered

Has any of this been independently tested?Έχει ελεγχθεί ανεξάρτητα κάτι από αυτά;

Honestly: partly. We run our own adversarial testing — we deliberately attack our platform and publish what happened, including the isolation results on this page and the failure testing on our reliability page. What we have not yet had is a third-party penetration test of Grandhosting, and we would rather say so than imply otherwise. When we commission one, we will say that too.

Ειλικρινά: εν μέρει. Κάνουμε δικές μας επιθετικές δοκιμές — επιτιθέμεθα σκόπιμα στην πλατφόρμα μας και δημοσιεύουμε τι συνέβη, μαζί με τα αποτελέσματα απομόνωσης σε αυτή τη σελίδα και τις δοκιμές αστοχίας στη σελίδα αξιοπιστίας. Αυτό που δεν έχουμε ακόμη είναι έλεγχος διείσδυσης (penetration test) από τρίτο φορέα για το Grandhosting, και προτιμούμε να το πούμε παρά να υπονοήσουμε το αντίθετο. Όταν τον αναθέσουμε, θα το πούμε επίσης.

What happens if another site on the platform gets hacked?Τι γίνεται αν χακαριστεί ένα άλλο site στην πλατφόρμα;

Nothing reaches you. Each site runs in its own isolated environment with its own database, and network rules stop one site from reaching another at all. That is the failure that takes down whole shared servers elsewhere, and it is the specific thing this architecture exists to prevent.

Δεν σας αγγίζει τίποτα. Κάθε site τρέχει στο δικό του απομονωμένο περιβάλλον με τη δική του βάση δεδομένων, και οι κανόνες δικτύου εμποδίζουν εντελώς ένα site να φτάσει σε άλλο. Αυτή ακριβώς η αστοχία ρίχνει ολόκληρους κοινόχρηστους servers αλλού, και είναι το συγκεκριμένο πράγμα που αυτή η αρχιτεκτονική υπάρχει για να αποτρέψει.

Where is my data actually stored?Πού αποθηκεύονται πραγματικά τα δεδομένα μου;

In the European Union, and it does not leave. Your site is hosted mainly in Germany, always within the EU, in ISO 27001-certified data centres, and backups are kept on separate storage in the EU. Some of the companies behind that infrastructure are incorporated in the United States: every one is named in our Data Processing Agreement, with the data kept in an EU region under Standard Contractual Clauses.

Στην Ευρωπαϊκή Ένωση, και δεν φεύγει από εκεί. Το site σας φιλοξενείται κυρίως στη Γερμανία, πάντα εντός ΕΕ, σε κέντρα δεδομένων πιστοποιημένα κατά ISO 27001, και τα αντίγραφα ασφαλείας φυλάσσονται σε ξεχωριστό αποθηκευτικό χώρο εντός ΕΕ. Ορισμένες από τις εταιρείες πίσω από αυτή την υποδομή εδρεύουν στις ΗΠΑ: όλες κατονομάζονται στη Σύμβαση Επεξεργασίας Δεδομένων μας, με τα δεδομένα να παραμένουν σε περιοχή ΕΕ υπό Τυποποιημένες Συμβατικές Ρήτρες.

Can I see what the firewall blocked on my site?Μπορώ να δω τι μπλόκαρε το firewall στο site μου;

Yes — and you can act on it yourself. Your dashboard lists each blocked request with the rule that triggered it, so if a legitimate action of yours was caught you can lift that specific rule with one click instead of opening a ticket and waiting.

Ναι — και μπορείτε να ενεργήσετε μόνοι σας. Το dashboard σας εμφανίζει κάθε μπλοκαρισμένο αίτημα μαζί με τον κανόνα που το ενεργοποίησε, οπότε αν μια νόμιμη ενέργειά σας παγιδεύτηκε, μπορείτε να άρετε τον συγκεκριμένο κανόνα με ένα κλικ αντί να ανοίξετε αίτημα υποστήριξης και να περιμένετε.

What if I need to get an old version of my site back?Τι γίνεται αν χρειαστεί να επαναφέρω μια παλιά έκδοση του site μου;

Every site is backed up nightly to storage that is entirely separate from the server it runs on, kept for 30 days, and restored with one click. We also test that those backups actually restore — not just that the files exist, but that the recovered site matches the live one, content included.

Κάθε site λαμβάνει νυχτερινό αντίγραφο ασφαλείας σε αποθηκευτικό χώρο εντελώς ξεχωριστό από τον server όπου τρέχει, διατηρείται για 30 ημέρες και επαναφέρεται με ένα κλικ. Επίσης ελέγχουμε ότι αυτά τα αντίγραφα όντως επαναφέρονται — όχι απλώς ότι τα αρχεία υπάρχουν, αλλά ότι το ανακτημένο site ταιριάζει με το ζωντανό, μαζί με το περιεχόμενο.

Founding Member pricing.
Yours while you stay.

From €3.49/mo + VAT — pay only for what your site actually uses. Founding-member pricing stays locked for as long as your account remains active.

Early access means direct access to our team. You’re not a ticket number. You’re a founding partner.

No commitment and no card to start. Takes a minute.

Create your account →

Already hosted elsewhere? Managed migration, zero downtime →