Overview #
Security on Xponent is layered and mostly invisible to you: we handle it so you can run your business. This article explains the layers protecting your site and what your role is.
The Security Layers #
| Layer | What it does |
|---|---|
| Managed infrastructure | Isolated GridPane containers, hardened server baseline, automatic core updates |
| Patchstack protection | Real-time vulnerability monitoring and virtual patching for WordPress plugins |
| Web application firewall (WAF) | Blocks malicious traffic before it reaches your site |
| SSL everywhere | Auto-renewing HTTPS certificates on all sites |
| Brute-force protection | Login throttling and failed-attempt lockdowns |
| Automated backups | Off-site backups so any incident is recoverable |
Monitoring & Response #
- Patchstack alerts: if a vulnerability is found in any plugin, we’re notified immediately and patch or mitigate before it becomes a problem.
- Better Stack uptime: 15-minute checks with alerts routed to our team.
- Proactive updates: plugin updates are applied and tested by us on a schedule (see How Xponent Keeps Your Site Updated).
Your Role in Security #
- Use strong passwords and enable 2FA where available (see Users & Access).
- Don’t install random plugins: each one adds risk. Request plugins through Xvault so we vet and license them.
- Report anything unusual: unexpected emails, strange admin accounts, or site behavior. Tell us; it’s always better to check.