Security and Trust

CloudSonic is a managed cloud hosting platform founded in 2026, built for WordPress but flexible enough to run any application stack. Every server includes full root SSH access, a pre-configured performance and security stack, and Cloudflare Enterprise on every plan.

Platform Security Controls

Every CloudSonic server is provisioned with the following security controls active by default; no configuration required on your part.

Network and Perimeter

UFW restricts all inbound traffic to ports 80, 443, and 2222 from the moment a server is provisioned. CrowdSec monitors Nginx, SSH, and PHP-FPM logs in real time, feeding block decisions to iptables using threat intelligence gathered across millions of deployments worldwide. Fail2ban catches brute force attempts against SSH and WordPress login endpoints that slip through before CrowdSec’s community blocklist identifies the source. Cloudflare Enterprise sits in front of every site on every plan, providing DDoS mitigation, WAF protection, and bot management at the network edge before traffic reaches your server.

Process Isolation

AppArmor enforces mandatory access control policies for every key process on your server including Nginx, PHP-FPM, MySQL, and Redis, restricting each to only the files, directories, and system calls it legitimately requires. If any process is compromised, AppArmor prevents it from reading sensitive files, writing outside its permitted directories, or spawning unexpected child processes.

Access Control

SSH is available on port 2222 only, with password authentication disabled and public key authentication required on every server. Tailscale creates a private WireGuard network between your server and your devices, allowing SSH access and all monitoring infrastructure to be restricted to your private Tailscale network without exposing those services to the public internet.

Encryption and Certificates

Let’s Encrypt SSL certificates are provisioned automatically during site setup and renewed automatically before expiry. For sites behind Cloudflare Enterprise, SSL terminates at the Cloudflare edge with a separate certificate, and the connection between Cloudflare and your origin server is encrypted with a CloudSonic-managed origin certificate. All internal service communication between Nginx, PHP-FPM, and Redis runs over Unix sockets rather than TCP ports, eliminating network-layer exposure between processes on the same server.

Monitoring and Visibility

Prometheus exporters for Node Exporter, Nginx, PHP-FPM, Redis, MySQL, and PostgreSQL run on every CloudSonic server, all bound to localhost and accessible only via Tailscale. No monitoring port is ever exposed to the public internet. Grafana dashboards connect to your Prometheus instance over your private Tailscale network, giving you full visibility into server performance without opening a single public port.

Memory and Process Protection

earlyoom runs on every server as a safety net against memory exhaustion, terminating low priority processes before the Linux kernel’s own out-of-memory killer takes over. Nginx, PHP-FPM, Redis, MariaDB, and PostgreSQL are explicitly protected from earlyoom termination, ensuring your web server and database survive memory pressure events caused by any other process on the server.

Subprocessors

CloudSonic uses the following third-party services to deliver and operate the platform. Where infrastructure region is customer-configurable, this is noted below.

Cloudflare
Cloudflare Security & Performance
Regional
Google Cloud Platform
Google Cloud Platform Hosting Infrastructure
Customer's Choice
Vultr
Vultr Hosting Infrastructure
Customer's Choice
Hetzner
Hetzner Hosting Infrastructure
European Union
DigitalOcean
DigitalOcean Hosting Infrastructure
Customer's Choice
Amazon Web Services
Amazon Web Services Hosting Infrastructure
Customer's Choice
Backblaze
Backblaze Backup Storage
United States
Tailscale
Tailscale Private Networking
United States
SendGrid
SendGrid Transactional Email
United States
Anthropic
Anthropic AI Services
United States
OpenAI
OpenAI AI Services
United States

Compliance

CloudSonic operates on infrastructure held by certified cloud partners. The following certifications are held by our infrastructure providers and by CloudSonic directly.

Hosting Partners Certifications

  • ISO 27001 ISO 27001
  • ISO 27017 ISO 27017
  • ISO 27018 ISO 27018
  • SOC 2 Type II SOC 2 Type II
  • SOC 3 SOC 3

CloudSonic Compliance

  • GDPR GDPR
  • Australian Privacy Act 1988 Australian Privacy Act 1988
  • CCPA CCPA

Backup and Data Recovery

Every CloudSonic server is backed up daily using Restic, with encrypted and deduplicated snapshots pushed off-server to Backblaze B2. Seven daily recovery points and one monthly snapshot are retained. Restores covering individual files, a specific database, or a complete application are available with one click from your CloudSonic dashboard.

Responsible Disclosure

If you discover a security vulnerability in CloudSonic’s platform, please report it through our Responsible Disclosure Policy. We commit to acknowledging all reports promptly and working to resolve confirmed vulnerabilities as a priority.

Legal and Compliance

CloudSonic’s full legal documentation is available in our Legal Centre.