Imunify360 Active Always-On Protection

Web hosting security.
Built in. Always on.

Every Alterascape plan ships with a complete web hosting security stack — Imunify360 AI malware scanning, Web Application Firewall, CloudLinux account isolation, daily off-site backups, and unlimited free SSL certificates. No security tiers, no upsells, no exceptions.

Get Protected Hosting View Pricing
🛡 Imunify360 Security Real-time threat monitoring SECURE THREAT ACTIVITY — LAST 24H Files Scanned Today 48,291 Threats Blocked 0 ✓ All Clear WAF ON Isolation ON Backups DAILY SSL AUTO Last full scan completed 2 minutes ago · 0 threats found SSL Rating A+ Account Isolation Filesystem · Process · Network All layers active
24/7
Real-time scanning, every account, every minute
A+
SSL Labs rating on all plans by default
30d
Off-site backup retention, daily snapshots
0
Extra cost for any security feature — all included
Defence in Depth

Six layers of security.
All of them included.

Security shouldn't be a checkbox you pay extra for. Every Alterascape plan ships with the full stack — from kernel-level hardening to automatic SSL renewal.

Imunify360 AI Scanner

Machine-learning malware detection scans every file on your account in real time. Threats are neutralised automatically — no manual intervention needed.

Web Application Firewall

Imunify360's WAF blocks SQL injection, XSS, CSRF, remote file inclusion, and CMS-specific exploits before they reach your application code.

Account Isolation

Your filesystem, PHP processes, and resources run in a fully isolated environment. A breach on another account can never reach yours.

Daily Off-Site Backups

Nightly full-account backups stored on separate infrastructure. 30-day retention. One-click restore from Plesk — no ticket required.

Free Unlimited SSL

Every domain gets a free Let's Encrypt SSL certificate. Auto-provisioned, auto-renewed, and reflected instantly in Plesk. No limits, no fees.

Brute-Force Protection

Failed login attempts are monitored server-wide. Attackers are rate-limited and blocked automatically before they can reach your credentials.

Imunify360 by CloudLinux

AI-powered security
that never sleeps.

Imunify360 is the industry standard for server-level security — used by tens of thousands of hosting providers worldwide. On Alterascape, it's not an optional upgrade. It's running on every account, every moment.

Real-Time Malware Scanning

Every file upload and modification is scanned instantly using Imunify360's ML model — trained on millions of real-world malware samples.

Web Application Firewall

Continuously updated WAF rules block known attack signatures for WordPress, Drupal, Joomla, and custom applications at the network edge.

Brute-Force & Bot Protection

Intelligent rate-limiting and IP reputation scoring stops credential-stuffing and brute-force attacks before they consume server resources.

Kernel-Level Hardening

CloudLinux OS patches the kernel with additional exploit mitigations and restricts process privileges far beyond a standard Linux install.

IMUNIFY360 — LIVE LOG
Scanning
03:41:12 [SCAN] public_html/index.php — clean
03:41:13 [SCAN] public_html/wp-login.php — clean
03:41:14 [WAF] SQLi attempt — blocked 104.21.x.x
03:41:14 [BLOCK] IP 104.21.x.x added to blocklist
03:41:15 [SCAN] public_html/themes/style.css — clean
03:41:16 [SSL] example.com cert renewed — 90 days
03:41:17 [SCAN] wp-content/uploads/ — 0 threats
03:41:18 [WAF] XSS attempt — blocked 185.220.x.x
03:41:19 [SCAN] public_html/config.php — clean
03:41:20 [BACKUP] Off-site backup completed — 1.2GB
CloudLinux Account Isolation

Your account.
Completely
your own.

Standard shared hosting puts every customer in the same environment. Alterascape uses CloudLinux to enforce hard isolation between every account — filesystem, processes, and network.

Filesystem Isolation

Your files are not accessible by any other account on the server — ever. Symlink attacks are blocked at the kernel level.

Process Isolation

PHP and application processes run under your account's UID only. No shared process space, no privilege escalation risk.

Breach Containment

If another customer's site is compromised, the isolation layer prevents lateral movement to your data or processes entirely.

Isolation Layer — Active
CloudLinux

Filesystem access: account-scoped only
PHP processes: isolated per UID
Cross-tenant symlinks: blocked
Resilience & Encryption

Backups and SSL.
Both automatic. Both free.

Security isn't only about blocking attacks — it's about recovering cleanly when something goes wrong, and encrypting everything in transit.

Daily Off-Site Backups

Your entire account is backed up every night to off-site storage on physically separate infrastructure. Not on the same server — on completely separate hardware in a separate facility.

30-Day Retention & One-Click Restore

30 days of rolling backups means you can recover from a mistake made weeks ago. Restore individual files, directories, databases, or an entire account — directly from Plesk, no ticket needed.

Encrypted Backup Transfers

Backup data is encrypted in transit between your account and off-site storage. Your data never travels over an unencrypted channel — backup or otherwise.

Free Unlimited SSL Certificates

Every domain on your account gets a free SSL certificate via Let's Encrypt. There's no limit on the number of certificates and no renewal fees — ever.

Automatic SSL Renewal

SSL certificates are renewed automatically before they expire. You'll never receive a browser security warning because of a forgotten renewal. It just works.

A+ SSL Configuration

Our servers are configured to modern TLS standards — TLS 1.2 and 1.3, strong cipher suites, HSTS, and OCSP stapling — achieving an A+ rating on SSL Labs out of the box.

FAQ

Security questions,
answered plainly.

What security software does Alterascape use?
Every Alterascape plan includes Imunify360 — the industry-leading AI-powered security suite from CloudLinux that combines a Web Application Firewall, real-time malware scanner, brute-force protection, and kernel-level hardening. It runs continuously in the background on every shared web hosting, WordPress hosting, Drupal hosting, VPS, and dedicated server plan.
How does Imunify360 protect my website?
Imunify360 uses machine learning to identify and neutralise malware, suspicious files, and attack patterns in real time. It scans every file on your account continuously, blocks known attack vectors through its WAF ruleset, and prevents brute-force login attacks by monitoring and rate-limiting failed authentication attempts across the server.
Is my hosting account isolated from other customers?
Yes. Every Alterascape shared hosting account runs in a fully isolated environment powered by CloudLinux: your filesystem is not accessible to other accounts, your PHP processes execute under your account only, and resource usage is capped independently. If another customer's site is compromised, the isolation layer prevents lateral movement to your data.
How often are backups performed, and where are they stored?
Full account backups run every night and are stored off-site — on separate infrastructure from your live server. Backups are retained for 30 days. You can restore any file, directory, or entire site in minutes through the Plesk control panel without opening a support ticket.
Do I need to pay extra for SSL certificates?
No. Every domain on your Alterascape account gets a free SSL certificate, automatically provisioned via Let's Encrypt and auto-renewed before expiry. There are no certificate limits, no renewal fees, and no manual steps required. HTTPS is enabled from the moment you point your domain.
What is a Web Application Firewall (WAF) and how does it help?
A Web Application Firewall sits in front of your website and inspects incoming HTTP requests for known attack patterns — SQL injection, cross-site scripting (XSS), remote file inclusion, WordPress exploits, and more. Imunify360's WAF ruleset is updated continuously to block newly discovered attack signatures before they can reach your application code.
Does web hosting security work on WordPress and Drupal sites?
Yes — and it goes further. Imunify360 includes CMS-specific WAF rules for WordPress, Drupal, and Joomla that block exploits targeting known plugin vulnerabilities, outdated core versions, and theme security gaps. These rules are updated automatically as new CVEs are published, so your sites stay protected even if an update hasn't been applied yet.
What happens if my website gets hacked or infected with malware?
Imunify360 detects and quarantines malware automatically — in most cases before you're even aware of it. If a file is flagged, it is moved to a secure quarantine and you receive an alert. You can restore clean versions instantly from daily backups retained for 30 days. Our support team is available 24/7 to assist with any security incident.
Is the security stack included on all hosting plans?
Yes. Imunify360 AI protection, WAF, and brute-force prevention are included on every web hosting, WordPress, Drupal, VPS, and dedicated server plan. On VPS and dedicated servers, Plesk Obsidian and CloudLinux are pre-installed alongside Imunify360 — no additional configuration required.
All Plans

Security-first hosting
for every use case.

Every product tier comes with the full security stack — no plan leaves without Imunify360, isolation, backups, and SSL.

Stop hoping your host
takes security seriously.

Launch on a platform where every plan ships with the full security stack. No upsells. No add-ons. Just protected hosting from day one.

Get Started — Security Included Compare Plans
Imunify360 on every plan
Free SSL & daily backups
Account isolation always-on
30-day money-back guarantee