TL;DR AppArmor
AppArmor is active on every CloudSonic server, providing mandatory access control that limits what compromised processes can do at the operating system level.
AppArmor is a Linux security module active on every CloudSonic server from the moment it is provisioned. It enforces mandatory access control policies that restrict what each process can read, write, and execute, limiting the damage a compromised application can do at the operating system level. It works alongside CrowdSec, UFW, and Fail2ban as one of four independent security layers on every CloudSonic server.
AppArmor Server Hardening on CloudSonic
CloudSonic loads AppArmor profiles for every key process on your server including Nginx, PHP-FPM, MySQL, and Redis, restricting each to only the files, directories, and system calls it legitimately needs. If any process is compromised through a vulnerability, AppArmor prevents it from reading sensitive files, writing outside its permitted directories, or spawning unexpected child processes. It operates silently in the background and works alongside CrowdSec, UFW, and Fail2ban as one of four independent security layers active on every CloudSonic server.