
Security Policy
Security policies for our projects and hosted sites
We take website security seriously and follow modern best practices to prevent and mitigate security-related incidents across the projects we build and manage. Our work includes sites for banks, national brands, and other security-sensitive organizations.
Modern hosting services
We host our sites on reputable managed hosting platforms with proven security track records. Our hosts handle infrastructure patching, provide daily backups, and issue vulnerability reports on outdated software.
We encourage clients to run their edge traffic through a managed web application firewall for geo-blocking, IP filtering, and denial-of-service mitigation.
Modern credential storage
Credentials are a common source of breaches. Administrative passwords are unique, randomly generated, and stored in a modern password manager. Multi-factor authentication is enforced on our hosting and infrastructure accounts.
Vulnerability monitoring and patching
WordPress core, plugins, and themes require frequent updates to stay ahead of newly disclosed vulnerabilities. We monitor multiple independent sources for threats, including Wordfence Threat Intelligence and the CISA Known Exploited Vulnerabilities catalog, and apply routine updates weekly. Critical vulnerabilities are patched within 24 hours of disclosure.
Custom code we write is linted and scanned for vulnerabilities before it is deployed.
Backups and recovery
Our hosts take daily snapshots of every site, retained for at least 30 days. Backups let us revert unwanted changes and investigate incidents. Backups are not accessible from the live sites.
Monitoring and alerts
We use multiple tools and services for continuous monitoring of uptime, errors, administrative activity, and potential security issues. All of our sites have Wordfence, iThemes Security Pro, or a comparable application-layer firewall installed to provide an additional layer of defense and to alert us to suspicious activity in real time.
Limited access
We encourage clients to minimize the number of administrative accounts and to restrict administrator access by IP where possible. XML-RPC is disabled on our sites, and REST API user enumeration is blocked.
We audit our sites for inactive accounts and other potential issues that haven’t already been handled by the processes above.
Incident reports
When a compromise is detected, we act within the first hour to mitigate damage — patching, rolling back, or placing the site in maintenance mode as needed — and notify the client immediately. If mitigation isn’t possible quickly, we restore the most recent backup.
How you can help
Weak and reused passwords on administrative accounts can still give attackers access to sites. Please use a modern password manager to generate and store unique, random passwords, and enable multi-factor authentication wherever it’s offered.