
At Ecenica Hosting, we take the security of your websites, email and domains incredibly seriously. It’s at the core of everything we do.
We’ve recently seen a rise in automated security scans targeting hosting providers across the industry. It might be that you’ve received such an email. Whilst we can’t talk for other hosts, at Ecenica we welcome responsible disclosure; however, we wanted to explain why these external assessments often give an incomplete and sometimes misleading picture of our actual security measures and how we protect your data.
Our Security Approach
Ecenica Hosting’s systems are secure, properly maintained and built on reliable security foundations. External security scans and automated assessments sometimes give misleading information about our security. Put simply, these surface-level checks simply can’t detect the comprehensive security measures we have in place behind the scenes.
Think of it like judging a bank’s security by only looking at the front door. You might see what appears to be a simple entrance, but you’re missing the reinforced walls, alarm systems, security cameras, trained guards and vaults that actually keep it secure.
Similarly, it’s not in the bank’s interest to advertise their security systems.
What Makes Our Security Different
Here’s what sets Ecenica Hosting apart when it comes to protecting your data and systems:
We Don’t Just Patch, We Stay Ahead
Ecenica Hosting’s infrastructure operates under extended security policies that go far beyond what most providers offer. We deploy the latest Linux operating systems on new servers and purchase commercial long-term support licenses for OS versions across our entire infrastructure. But here’s the key difference: we don’t just apply patches when vulnerabilities are discovered, we proactively implement security measures that prevent issues before they become problems.

Layer Upon Layer of Protection
Our security is built on a carefully chosen system of protective layers which we call Ecenica SiteProtect. Features include;
- CloudLinux Security: Enterprise-grade kernel-level protection with advanced isolation and hardening
- Advanced AI-powered Firewall Systems: Multi-tier firewall protection with intelligent threat detection and blocking
- Imunify360 Integration: Comprehensive security suite providing real-time malware scanning, intrusion detection, and automated response capabilities
- Regular Security Updates: Systematic patching and update processes following industry best practices
Security which extends beyond IT systems
Here’s something most web hosting providers won’t tell you: the biggest security vulnerabilities often come from human factors, not technical ones. That’s why our approach to security extends far beyond just systems:
Our Team Makes the Difference
We’re not just another hosting company with a large, rotating staff. Our core team brings over 25 years of combined IT experience, with graduate-trained professionals holding formal qualifications in Information Systems (B.Sc) and related fields. When you have a small, dedicated team with intimate knowledge of every system, security becomes personal.
Security by Design, Not by Accident
- Our team maintain a deliberate low-profile online presence.
- Our secure datacenter facilities feature physical access controls and comprehensive monitoring. ID checks, CCTV, physically secured hardware.
- Access is strictly limited to essential core team members only.
- We never share access with third parties. We maintain complete control over our infrastructure at every stage.
- Every team member operates under managed access based on role requirements and the principle of least privilege
Why External Scans Get It Wrong
External security tools face some fundamental limitations when trying to assess our infrastructure:
The “Iceberg Effect”
What these scans see is just the tip of the iceberg. They might detect version numbers in server banners, but they can’t see:
- Backported security patches that maintain version numbers while fixing vulnerabilities
- Custom security hardening implementations we’ve developed over decades
- Advanced protection mechanisms running at the kernel level
- Security modules that operate completely transparently to external tools
No Backdoors
Our systems undergo regular security audits, and we follow established security frameworks specifically designed to prevent malicious access vectors.
Why We Don’t Share Everything
You might wonder why we don’t publish detailed information about our security measures. There’s a good reason for that. For operational security, we don’t publicly disclose comprehensive details about our security implementations. This includes specific software versions, custom hardening procedures, detailed firewall configurations, and our internal monitoring capabilities. We’re happy to discuss our general approach and capabilities, but sharing detailed implementation specifics would be like publishing the combination to our vault.
Our Ongoing Commitment
Security isn’t a destination, it’s a journey. At Ecenica Hosting, we maintain:
- 24/7 Proactive Monitoring: Our security doesn’t sleep, and neither do our monitoring systems
- Continuous Updates: We detect problems before they become a problem.
- Industry Compliance: We adhere to established security standards and best practices
- Rapid Response: When security events do occur, we have established procedures to handle them swiftly and effectively
We appreciate when security researchers and groups take the time to identify potential vulnerabilities, it shows the community cares about overall internet security. However, we also want our customers to understand that surface-level scans simply cannot capture the full picture of our security posture.
If you believe you’ve identified a genuine security concern with our infrastructure, we encourage you to reach out through our official contact channels. We take every report seriously and investigate thoroughly. Please note we do not pay bounties, or pay for disclosures.
Have questions about our security? Contact our Sales team, we’re always happy to discuss how we keep your data safe.