Security Architecture // Active Defense

Your Website Sits Behind Layers.

Before traffic reaches your hosting account, Fusion Arc Hosting surrounds it with multiple security boundaries designed to inspect, filter, isolate, contain and recover. DDoS mitigation, Imunify360 firewall and WAF inspection, CloudLinux CageFS isolation, malware detection, automated cleanup, email protection and offsite recovery work together as one security architecture.

Imunify360CloudLinux CageFSDDoS ProtectionImunifyEmailOffsite Recovery
FAH SECURITY CORE DEFENSE // ISOLATION // RECOVERY
EDGE FILTER TRAFFIC CONTROL
WAF ENGINE REQUEST INSPECTION
CAGEFS ACCOUNT ISOLATION
MALWARE SCAN + CLEANUP
Defense In Depth

One Firewall Is Not A Security Strategy.

Serious hosting security assumes threats can arrive through more than one path. Fusion Arc Hosting stacks independent defensive controls so malicious activity must survive multiple security boundaries before it could ever reach a hosted application.

01
NET

DDoS Traffic Defense

High-volume and abusive network traffic is confronted at the perimeter instead of being treated like ordinary application workload.

Network Perimeter Active
02
FW

Imunify360 Firewall

Suspicious IP activity, automated abuse and hostile request behavior encounter server-side security controls before receiving normal access.

Firewall Defense Active
03
WAF

Web Application Firewall

HTTP traffic is inspected for exploit patterns, malicious payloads and suspicious behavior before the request reaches WordPress, PHP or another CMS.

Request Inspection Active
04
MAL

Malware Detection

Website files can be scanned for malicious code, compromised scripts and other indicators of an infected hosting account.

File Protection Active
05
CFS

CloudLinux CageFS

Hosting accounts operate within isolated filesystem environments so customers do not receive unrestricted visibility into neighboring accounts.

Tenant Isolation Active
06
SMTP

ImunifyEmail Protection

Outbound email protection helps contain malicious or abusive sending behavior originating from compromised mailboxes, scripts or hosting accounts.

Mail Defense Active
Imunify360 // Firewall + WAF

Every Request Has To Earn Its Way Through.

Legitimate customers should reach your website. Exploit attempts, abusive automation and malicious requests should not. Traffic is evaluated before it continues toward the hosting account and application.

FAH://EDGE/REQUEST-INSPECTION ● INSPECTION ENGINE ACTIVE
Internet
IMUNIFY360 FIREWALL // WAF // INSPECTION
Your Website
HTTPS /index.php ALLOW
POST /wp-login.php CHECK
GET ?payload=... BLOCK
POST /xmlrpc.php FILTER
HTTPS /products/ ALLOW
APPLICATION REQUEST INSPECTED
MALICIOUS PATTERN BLOCKED
LEGITIMATE REQUEST FORWARDED
Network Perimeter Defense

Flood The Edge. Not Your Website.

Distributed denial-of-service attacks attempt to overwhelm infrastructure by converting traffic volume into resource exhaustion. DDoS protection is positioned ahead of the application layer so hostile traffic does not automatically become website workload.

01
Traffic Reaches The Edge Incoming traffic encounters network controls before application processing.
02
Abnormal Traffic Is Identified Suspicious volume and abusive patterns can be separated from ordinary visitors.
03
Legitimate Traffic Continues The goal is to keep real visitors moving while unwanted traffic is mitigated.
Website File Defense

Malware Does Not Get A Free Apartment.

Vulnerable plugins, compromised credentials and malicious uploads can place hostile code inside an individual website. Security therefore continues beyond the network and application boundary into hosted account files.

IMUNIFY360://MALWARE-SCANNER ● FILE SCAN ACTIVE
/public_html/wp-config.php CLEAN
/public_html/index.php CLEAN
/public_html/wp-content/uploads/cache.php DETECTED
/public_html/wp-content/themes/site/functions.php CLEAN
/public_html/wp-admin/admin.php CLEAN
/public_html/.htaccess CLEAN

Automated Malware Cleanup

When malicious files are detected, automated cleanup capabilities can remove the infection rather than simply generating an alert and leaving the compromised file behind.

Malware scanning ENABLED
Automated cleanup ENABLED
Customer control OPT-OUT AVAILABLE
Website-level security ACTIVE
CloudLinux // CageFS // LVE

Your Neighbor Is Not Your Trust Boundary.

Shared hosting does not need to mean one giant shared security context. CloudLinux separates customer environments so activity can be contained to the account where it belongs.

ACCOUNT_ALPHA CAGEFS://LOCKED
ACCOUNT_BRAVO CAGEFS://LOCKED
YOUR_ACCOUNT CAGEFS://LOCKED
FILESYSTEM ISOLATION ACCOUNT BOUNDARIES LVE RESOURCE CONTAINMENT CAGEFS ENABLED
Security Lifecycle

Defense Before. Containment During. Recovery After.

Prevention matters, but security also needs a plan for what happens after something goes wrong. Fusion Arc Hosting combines system patching, encrypted connections and independent recovery mechanisms into the same defensive model.

KERNEL

KernelCare Live Security Patching

Eligible Linux kernel security fixes can be deployed without waiting for the next traditional reboot cycle, reducing the exposure window between a security fix and a protected running kernel.

PATCHING://LIVE

SSL/TLS Encryption

Automated SSL management helps keep supported domains encrypted over HTTPS so credentials, website forms and visitor traffic are not transmitted as ordinary plaintext.

TRANSPORT://ENCRYPTED

Offsite Recovery Layer

Backup copies maintained separately from the live hosting filesystem create an independent recovery path if website data becomes corrupted, deleted or compromised.

RECOVERY://OFFSITE
Request Path

Trace A Request Through The Defense Stack.

01
Internet Inbound request
02
DDoS Layer Traffic mitigation
03
Firewall Source evaluation
04
WAF Request inspection
05
CageFS Account isolation
06
Application Site processing
07
Filesystem Malware defense
Threat → Response

Different Threats. Different Control Layers.

Security is stronger when every attack does not depend on one defensive control. Different threats are confronted at the point in the infrastructure where containment makes the most sense.

SYN
DDoS / Traffic Flood

Network mitigation helps prevent abusive traffic from becoming normal application load.

WAF
Malicious Web Request

Imunify360 firewall and WAF controls inspect and filter suspicious application traffic.

PHP
Compromised Website Code

Malware security can identify malicious files residing inside individual website accounts.

FS
Cross-Account Access

CloudLinux CageFS establishes filesystem boundaries between separate hosting users.

SMTP
Compromised Mail Sender

ImunifyEmail and outbound sending controls help contain malicious email activity.

CVE
Kernel Vulnerability

KernelCare reduces dependence on traditional reboot windows for eligible security patches.

TLS
Traffic Interception

SSL/TLS encrypts supported connections between visitors and hosted websites.

BAK
Damaged Or Compromised Data

Offsite backups provide an independent restoration path outside the live filesystem.

Infrastructure Security Plane

Security Extends Beyond The Control Panel.

The website, operating system, network and recovery architecture are separate parts of the same security problem. Fusion Arc Hosting carries the defensive model through the infrastructure underneath your hosting account.

NETWORK EDGE DDoS mitigation and traffic defense
HOST SECURITY Kernel, Imunify360 and operating-system protection
RECOVERY PLANE Independent offsite backup architecture
FAH SECURITY MULTI-LAYER CONTROL
Fusion Arc Hosting Security Stack

The Layers Protecting Your Hosting Environment.

01

DDoS Protection

Network-layer mitigation designed to reduce abusive and high-volume attack traffic before it reaches hosted workloads.

Network Defense
02

Imunify360 Firewall

Server-side firewall protection designed to identify and restrict hostile access patterns.

Firewall Defense
03

Web Application Firewall

Web requests are inspected for exploit signatures, malicious payloads and suspicious behavior.

Application Defense
04

Brute-Force Protection

Repeated authentication abuse can be identified and restricted rather than receiving unlimited attempts against protected services.

Access Defense
05

Intrusion Detection / Prevention

Suspicious server activity and repeated hostile patterns can be identified and blocked before they develop into unrestricted access attempts.

Intrusion Defense
06

Proactive Defense

Security continues beyond static filtering with additional protection aimed at malicious behavior deeper inside application execution.

Runtime Defense
07

Malware Scanning

Website files can be scanned for malicious code and known infection patterns residing inside hosted accounts.

File Defense
08

Automated Malware Cleanup

Detected website malware can be cleaned automatically, with customer opt-out control available for the cleanup feature.

Automated Remediation
09

CloudLinux CageFS

Each hosting user receives a restricted filesystem view designed to isolate customers from neighboring hosting accounts.

Filesystem Isolation
10

CloudLinux LVE Containment

Account-level resource boundaries help prevent one hosting account from freely consuming the entire shared environment.

Resource Isolation
11

ImunifyEmail

Outbound email protection helps identify and contain malicious or abusive sending behavior originating from hosted services.

Mail Security
12

Outbound Sending Boundaries

Sender, script, domain and hosting-account controls help constrain the blast radius of compromised email sources.

Abuse Containment
13

KernelCare Live Patching

Eligible kernel security fixes can be applied while the operating system remains online.

Operating-System Security
14

Automatic SSL/TLS

Supported domains receive HTTPS encryption through automated SSL certificate provisioning and management.

Transport Encryption
15

Offsite Backup Protection

Backup copies maintained away from the primary hosting filesystem create another recovery path from corruption, deletion or compromise.

Recovery Defense
16

RAID Storage Resilience

RAID storage configurations reduce dependence on a single physical storage device while remaining separate from the backup strategy.

Infrastructure Resilience
17

cPanel Account Boundaries

Websites, databases, mailboxes and application files remain tied to their own hosting account permissions and security context.

Account Isolation
18

Layered Incident Recovery

Protection is backed by operational recovery mechanisms so compromised content can be contained, cleaned and restored.

Defense In Depth
Fusion Arc Hosting Security

Hosting Should Be More Than A Server Connected To The Internet.

Put your website behind an architecture built around traffic defense, request inspection, account isolation, malware protection, outbound abuse containment, encryption, live security patching and independent recovery.

IMUNIFY360IMUNIFYEMAILCLOUDLINUXCAGEFSKERNELCAREDDOS DEFENSEOFFSITE RECOVERY
Security & Protection

Hosting protected at multiple layers.

Fusion Arc Hosting uses Imunify360 across our Web Hosting, Reseller Hosting, Agency Hosting, and CMS Hosting plans, providing an integrated security platform designed to detect threats, block malicious activity, scan for malware, and protect websites around the clock.

cloud-hosting

Network Firewall

Intelligent firewall protection continuously analyzes traffic and helps block malicious connections before they can threaten hosted services.

WebShield Protection

Suspicious web traffic can be filtered before reaching your website, helping defend against malicious requests and abusive activity.

Malware Scanning

Automated malware scanning and cleaning continuously checks hosted files for known and suspicious malicious code.

Proactive Defense

Imunify360 can identify dangerous PHP behavior while code executes, helping stop malicious activity before it causes damage.

6 LAYERS OF INTEGRATED DEFENSE

Security working together, not in isolation.

Modern website security requires more than a firewall. Imunify360 combines multiple security technologies into one integrated defense platform across supported Fusion Arc Hosting environments.

Built Different
AUTOMATED THREAT RESPONSE

Protection that keeps watching after you log out.

Attackers do not politely restrict themselves to business hours. Imunify360 continuously analyzes activity across the server and can automatically respond when suspicious behavior, malware, brute-force attempts, or exploit patterns are detected.

Intrusion Detection

Server logs and activity are continuously analyzed for patterns associated with attacks and suspicious behavior.

Automatic IP Blocking

Repeated failed login attempts, brute-force behavior, and other suspicious activity can trigger automatic blocking of offending IP addresses.

Server-Wide Protection

Protection extends beyond individual websites, helping secure services and applications operating throughout the hosting environment.

Continuous Monitoring

Security systems operate continuously, allowing threats to be detected and addressed without waiting for someone to manually notice them.

Imunify360 Included

Security protection is included across our Web Hosting, Reseller Hosting, Agency Hosting, and CMS Hosting plans.

Web Application Firewall

The WAF analyzes incoming requests and helps defend websites against common exploits, malicious requests, and suspicious traffic.

Malware Protection

Automated malware scanning helps identify compromised files and malicious code throughout supported hosting accounts.

Intrusion Prevention

Repeated failed login attempts and other suspicious patterns can be detected automatically, with offending IP addresses blocked when appropriate.

Integrated Server Hardening

Imunify360 includes server-hardening technologies designed to strengthen the underlying hosting environment, not merely individual websites.

HardenedPHP

This provides security fixes for supported older PHP versions that are no longer maintained by the original PHP developers, helping protect legacy applications that cannot yet be upgraded.

Security That Never Sleeps

Firewalling, traffic analysis, malware scanning, intrusion detection, and proactive defenses work together continuously across the hosting platform.

Proactive Defense

Suspicious PHP behavior can be detected while scripts are running, providing another defense against previously unknown or changing threats.