From the moment a packet hits our edge to the moment your database query returns, every layer of BizHostWiz is hardened, monitored, and audited.
Anycast-routed traffic is inspected at our network edge by 1.5 Tbps of DDoS scrubbing capacity. Volumetric attacks (SYN flood, UDP flood, amplification) are absorbed before they reach your server. Always on, no opt-in.
ModSecurity-powered WAF with the OWASP Core Rule Set (CRS) pre-loaded. Protects against SQL injection, XSS, RCE, LFI, and 300+ other web attacks. Per-customer rule allowlisting available.
Daily deep scans of every file on your account using ClamAV, ImunifyAV, and our own custom signatures. Infected files are auto-quarantined, and you can roll back to a clean backup in one click.
Free auto-renewing Let's Encrypt SSL on every domain and subdomain. TLS 1.3 enforced. AES-256 encryption at rest on all storage. Optional customer-managed keys (BYOK) on VPS and dedicated.
Automated daily backups retained for 30 days, stored on separate infrastructure in a separate datacenter. 1-click restore from your control panel or via our support team. Included free on every plan.
Mandatory TOTP-based 2FA for all accounts. IP whitelisting and SSH key enforcement on VPS and dedicated. Role-based access control (RBAC) for teams. SSO (SAML/OIDC) on enterprise plans.
Our SOC monitors every customer server 24 hours a day, 7 days a week, 365 days a year. We do not just collect logs "” we have trained incident responders on shift who triage, contain, and remediate in real time.
@lang('If you find a valid security vulnerability in our infrastructure, we will reward you and publicly credit you (if you want). Send details to security@bizhostwiz.com with a PGP-encrypted proof-of-concept.')