How we protect your platform
Every TurboStack host runs several security layers that Hosted Power manages for you. You do not configure these - they are on by default and kept up to date centrally.
Hardened base with automatic updates
Hosts run a hardened operating system, and security updates are applied automatically. The platform checks for updates several times a day and patches centrally, so known vulnerabilities are closed quickly without action from you.
Firewall
A firewall runs on every host and reacts to abuse within seconds. It watches failed logins across services (SSH, FTP, mail and HTTP) and bans repeat offenders automatically. See Firewall.
TurboShield
TurboShield rate-limits traffic per visitor and classifies bots, throttling abusive request rates before they overload the host. A throttled client receives a soft HTTP 429 response rather than a hard ban. See TurboShield and DDoS and abuse protection.
TurboRadar and malware protection
TurboRadar provides runtime threat detection and scans for commerce malware, watching for suspicious process behavior and known-bad files after your application is deployed. It detects and reports - findings surface in the host's Threat Center. Actively blocking malicious requests - injection attempts, distributed brute-force attacks and known exploits - is done by the Web Application Firewall (WAF), TurboShield and the Firewall.
Encryption, backups and traffic protection
- Free SSL/TLS (Secure Sockets Layer / Transport Layer Security) for your applications - see Access control and encryption.
- Managed daily backups - see Backups and recovery.
- Network-level Distributed Denial-of-Service (DDoS) mitigation - see DDoS and abuse protection.