№ 01 Security

Kept on, and yours to keep

Backups, patching, and certificates are handled for you, every day, without a ticket. Portability is the other half — your stack lives as code, so it's never stuck here.

№ 02 Backups

Backups

Automated, retained, and proven by restoring them — not a checkbox that's never been tested.

  • Daily backups

    Every account is backed up automatically, every day — no opt-in, no configuration required.

  • Retention

    Kept for 7 days by default. Extended backup retention (30-day) extends that to a 30-day window — daily backups kept for 30 days instead of 7.

  • Tested restores

    Backups are periodically restored to confirm they work — recovery is proven, not assumed.

    See what a tested restore actually is →
№ 03 Patching

Patching

OS and runtime security patching runs on a managed cadence — urgent issues don't wait for it.

Routine patching
Regular managed cadenceOS and runtime security patches are applied on a standing schedule — no ticket, no downtime you have to plan around.
Urgent CVEs
ExpeditedCritical vulnerabilities are triaged and patched outside the normal cadence, as soon as a fix is available.
Your action required
NonePatching is part of every plan — there is nothing to schedule, approve, or remember on your end.

See the full patch window, layer by layer →

№ 04 TLS & DNS

TLS & DNS

Certificates and records are managed as part of the platform — one less system to operate yourself.

  • Managed TLS

    Certificates are issued and renewed automatically. Every site and instance is HTTPS by default — no expiry surprises, no manual renewal.

  • DNS management

    Records are managed for you as part of the stack — pointed, propagated, and kept correct without a separate console to babysit.

Who owns what, the record sheet, and the certificate lifecycle →

The security headers every request gets by default, and what's left as a choice →

№ 05 Portability

Everything as code

The anti-lock-in differentiator: your stack is defined in a repo you hold, not a console only we can see.

  1. 1

    It's in a repo

    Infrastructure and configuration are defined as code, committed alongside the app — not clicked together in a console only we can see.

  2. 2

    No proprietary lock-in

    The stack is built from standard, portable pieces — no bespoke format or hidden state that only runs here.

  3. 3

    Leave any time, stack intact

    Take the repo and the config with you. Nothing about leaving requires a rebuild from scratch.

    See the handover procedure →

Who actually holds a key to it — the access matrix →

Ready to start?

Tell us what you're running — one fixed monthly rate, within a business day.

Get a quote