Server Security

Linux server security for the machine you already have.

We audit, harden and clean VPS and dedicated servers at your provider. SSH, firewall, Fail2Ban, malware and a compromised host. The account stays in your name.

Your server. Your provider. Our Linux expertise.

What we actually change

Less exposed surface, not a product installed on top

Most of the servers we see are not missing a security suite. They have password SSH, a panel on a public port, old PHP, and a WordPress admin that was never the problem until a plugin was. Hardening is the boring list: keys, firewall, updates, and who can still log in.

SSH keysfirewallFail2Banunattended updatespanel portsPHP version
Three jobs

Audit, harden, or clean up

€99from
Security audit

OS and update state, listening ports, SSH, firewall, backup status, obvious web shells and panel exposure. You get the findings. Fixes are separate if you want them.

Hardening

Key-only SSH, UFW or nftables, Fail2Ban, closed panel ports, security updates. We do not disable your access to do it. A second admin key stays in place until you confirm login.

€55 / hour
€149from
Compromised server

Malware, a new admin user, a miner, or mail suddenly queueing spam. Light WordPress cleanup starts at €149. A rooted box is usually a rebuild, quoted after the first look.

Full pricing →

After a break-in

Clean the files, or rebuild the server

Cleanup is enough when the OS is still yours

Infected themes, unknown WP users, a cron pulling a script. We remove them, rotate the passwords that were exposed, and check the web user cannot write the config.

Rebuild when root was not yours

A miner, a new UID 0, or an SSH key you did not add. Patching that host is how it comes back. We restore sites and mail onto a new server from a copy that predates the break-in.

Backup and restore →

Limits

No one can guarantee the server stays clean

In scope
SSHfirewallFail2Banmalware lookWordPress filesmail abuse
Not a promise
unhackableDDoS absorptionplugin code audit24/7 SOC

A volumetric attack is a provider or Cloudflare problem. We can put the site behind Cloudflare and lock the origin to their ranges. We do not sell mitigation capacity.

Independent since 2004

Access for an audit is temporary. After a compromise we prefer a dedicated key, removed when the job ends, and a password rotation you do yourself on the panel and the registrar.

Your server. Your provider. Our Linux expertise.

Need the server checked, or already compromised?

Tell us what you saw: a warning, a slow box, mail bouncing, or a user you did not create. We reply with the approach before any work starts.

Request Support → Contact Us