Security without theatre.
Hosting security starts with sensible defaults, controlled access, isolation, patching, and recoverable data—not a wall of badges.
Accounts
Administrative and customer access is separated by role. We use encrypted connections for account and management interfaces and restrict privileged access to people and systems that require it.
Servers and networks
DotMoose infrastructure is hardened before production use, with firewalling, restricted management access, logging, and regular operating-system and service updates. Customer workloads are separated according to the service type.
Web hosting
Shared-hosting accounts receive isolated service boundaries and resource limits provided by the selected hosting platform. TLS is part of normal website deployment, and privileged server access is not shared between customer accounts.
Backups
Backup features and retention depend on the product purchased. A backup should be independent from the system it protects; storage redundancy alone is not treated as a complete backup.
Customer responsibility
Customers are responsible for application updates, secure passwords, access they grant to others, and software they install unless a managed service explicitly includes those responsibilities.
Report a security issue
Send security reports to security@dotmoose.com. Include the affected hostname or IP, a clear description, timestamps, and enough detail for us to reproduce or investigate the issue.
Responsible testing
Please avoid destructive testing, denial-of-service activity, social engineering, accessing data that is not yours, or changing customer or production data. If you encounter sensitive information unexpectedly, stop and report what you observed without collecting more than is necessary to explain the issue.
DotMoose publishes the standard security.txt contact file so automated tools and researchers can find the current reporting address.