Architecture
Security
Cloud security

Cloud security

How SiteBox delivers a first line of defence for cloud based products

In the realm of digital security, the first line of defence is often the most crucial. At SiteBox Hosting, we've integrated our Cloud Security solution with Cloudflare Global Network to offer you an unparalleled level of protection. With Cloudflare's globally distributed nodes serving as the initial point of contact for all incoming internet traffic, we've created a security architecture that is not just robust but also efficient.

The unbypassable shield

One of the unique features of our Cloud Security is that the Cloudflare CDN serves as an unbypassable gateway to the internet. This means that every request directed toward your website must first pass through Cloudflare's nodes. Cloudflare's nodes are designed to intelligently process each incoming request. They scrutinise the payload and various attributes of the request to determine its legitimacy. Any request containing malicious elements or posing a risk to the origin server is promptly identified and dealt with, ensuring that only clean, safe traffic reaches your website. The beauty of this approach lies in its efficiency. By mitigating the most dangerous activities at the Cloudflare level, we minimise the load on your origin server and other infrastructure components. This leaves your resources free to handle legitimate traffic, ensuring optimal performance and availability.

Cloud security framework

To offer a more granular understanding of how our Cloud Security framework functions, we will present a part of our infrastructure chart that specifically focuses on the cloud technology responsible for intercepting all incoming requests to our infrastructure. It is built on 3 major components, each serving a unique role in fortifying your WordPress website's security and performance.

Cloud Infrastructure visualization

  1. Cloudflare WAF (Web Application Firewall) – this is the first layer of defence, responsible for identifying and blocking malicious web traffic based on a set of predefined rulesets. It serves as a filter that stands between your website and the broader internet, ensuring that only legitimate requests get through.
  2. Cloudflare Cache – beyond security, performance is a key concern for any website. Cloudflare Cache takes care of this by storing copies of your website's static and dynamic content. This reduces the load on the origin server and speeds up access for end-users, all while adding an additional layer of security.
  3. SiteBox Entrypoint Worker – this is a custom-built component that consists of various services designed to enhance both security and performance incorporating products like SiteBox Enclave, SiteBox Identity and SiteBox Accelerator.

Additional security practices

In addition to these core components, our security framework also incorporates several industry best practices to provide a stable and secure environments:

  • Full encryption in transit and at rest – all data, whether it's being transmitted over the network or stored on our servers, is fully encrypted. This ensures that your sensitive information is unreadable to unauthorised users at all times.
  • Free SSL certificate for each environment – we offer a free SSL certificate for every hosting environment, enabling secure, encrypted connections between your website and your visitors.
  • Required HTTPS for all incoming connections – to further enhance security, we mandate the use of HTTPS for all connections. This ensures that data transmitted to and from your website is always encrypted, reducing the risk of man-in-the-middle attacks.
  • Zero trust policies for all hosting services – in line with the principle of "never trust, always verify," our hosting services operate on a zero-trust model. This means that every request, internal or external, is verified before granting access, ensuring a more secure environment.