Our websites are hosted with 20i, and the answers provided below reflect the specific features and security standards they maintain.
1. Encryption Methods (Data in Transit and At Rest)
In Transit: 20i uses SSL/TLS certificates to encrypt all data moving between the server and the user. They provide free, automated Wildcard SSL certificates for every website via a partnership with Let's Encrypt. These certificates use industry-standard encryption protocols (TLS 1.2/1.3) and cover both primary domains and subdomains.At Rest: While 20i follow international standards for data at rest. Database, web, and mail servers operate on separate stacks to ensure data isolation.
2. Firewall Management and Malware Protection
Web Application Firewall (WAF): 20i employs a custom-built, enterprise-grade WAF that operates at the network edge. It inspects every HTTP request for threats like SQL injection, Cross-Site Scripting (XSS), and trojans.Malware Protection: They provide daily automated malware scans for all hosted sites. We can also run on-demand scans via the our control panel. If malware is detected, the system can automatically disable PHP Mail to prevent the site from being used for spam, and a detailed report is provided to help us clean the infection.
Network Defenses: They use StackProtect to block brute-force login attempts and employ network-level defenses that filter traffic based on IP reputation to block known attackers at the edge.
3. Disaster Recovery Plan
Timeline Backups: 20i's primary recovery tool is Timeline Backups, which takes automated daily snapshots of the website files and databases.Retention: Standard backups are kept for 30 days (files and databases).
Redundancy: They follow the 3-2-1 backup rule, storing backups on different server stacks.
Offsite Protection: Offsite backups are stored in a separate, geographically distinct data center to ensure recovery is possible even in the event of a total facility failure.
Restoration: We can restore specific files or directories.4. Automatic Updates for Core Components
Standard core features are updated automatically.
5. Security Policy
We hold a current Cyber Essentials certification.
6. SOC2 Compliance
Yes. 20i is ISAE 3000 SOC2 Type 2 compliant. This certification confirms that an independent auditor has verified their controls and procedures for security, availability, and data protection over an extended period. They also hold ISO 9001, ISO 27001, and ISO 22301 certifications.