How Xponent Secures Your Site

1 min read

Overview #

Security on Xponent is layered and mostly invisible to you: we handle it so you can run your business. This article explains the layers protecting your site and what your role is.

The Security Layers #

Layer What it does
Managed infrastructure Isolated GridPane containers, hardened server baseline, automatic core updates
Patchstack protection Real-time vulnerability monitoring and virtual patching for WordPress plugins
Web application firewall (WAF) Blocks malicious traffic before it reaches your site
SSL everywhere Auto-renewing HTTPS certificates on all sites
Brute-force protection Login throttling and failed-attempt lockdowns
Automated backups Off-site backups so any incident is recoverable

Monitoring & Response #

  • Patchstack alerts: if a vulnerability is found in any plugin, we’re notified immediately and patch or mitigate before it becomes a problem.
  • Better Stack uptime: 15-minute checks with alerts routed to our team.
  • Proactive updates: plugin updates are applied and tested by us on a schedule (see How Xponent Keeps Your Site Updated).

Your Role in Security #

  1. Use strong passwords and enable 2FA where available (see Users & Access).
  2. Don’t install random plugins: each one adds risk. Request plugins through Xvault so we vet and license them.
  3. Report anything unusual: unexpected emails, strange admin accounts, or site behavior. Tell us; it’s always better to check.

Related Articles #

Updated on August 31, 2026