Compliant Dedicated Hosting

For regulated & high-assurance buyers

Hosting you can put in front of a compliance team.

Single-tenant infrastructure, documented controls mapped to ISO 27001 Annex A and SOC 2 TSC, encryption with managed key custody, immutable audit logging, and machine-speed defense. Built to your requirements, operated by the same small team for 18 years.

Flagship tier · consult only

Compliant Dedicated

A scoped, single-tenant environment built to your compliance requirements on a discovery call, not bought from a cart. One tier to start, sized to your workload.

From $1,995/mo
plus a one-time onboarding engagement · annual prepay available
  • Dedicated single-tenant server, sized to workload
  • Signed security addendum (ISO 27001 Annex A + SOC 2 TSC)
  • At-rest encryption, key custody, immutable audit logs
  • UK or EU residency, signed DPA and SCCs
  • Machine-speed defense, named incident-response contact
Certification
ISO 27001
Roadmap Q1 2027 · addendum now
Residency
UK / EU
London or Frankfurt · DPA + SCCs
Where we actually stand

We lead with controls you can audit, not a logo.

A certification badge is a snapshot. What your compliance team can actually test is the set of controls a provider operates and can evidence on demand, and how fast it responds when something moves. That is what we put first. Today WebOps operates a documented control set, backed by a signed security addendum mapping each control to ISO 27001 Annex A and SOC 2 TSC, on infrastructure that is itself ISO 27001 certified and PCI-DSS compliant.

We are equally direct about the rest: WebOps does not yet hold its own ISO 27001 certificate, and we are on a funded roadmap to earn one, targeted for Q1 2027. Until then, the addendum, our controls documentation, and our independent vulnerability-scan and penetration-test results are evidence your auditors can hold in hand, not a promise to take on faith.

What Compliant Dedicated delivers

The things an institutional auditor asks for.

Built on the stack we already run, hardened and documented for buyers whose data cannot sit on shared infrastructure.

Single-tenant by design
A dedicated server for your environment alone. No shared LiteSpeed, no neighbor workloads, no multi-tenant blast radius.
Documented controls
A signed security addendum mapping the controls we operate to ISO 27001 Annex A and SOC 2 Trust Services Criteria.
Encryption with key custody
Encryption in transit and at rest, with a documented key-management story: where keys live, who has access, how they rotate.
Immutable audit logging
Write-once audit logs (Plesk admin, SSH auth, WAF, intrusion detection) shipped to object-locked storage with one-year retention.
UK or EU data residency
London or Frankfurt residency for adequacy under the Cayman DPA and GDPR. Signed DPA and Standard Contractual Clauses for any US transfer.
Machine-speed defense
An AI-operated defense layer watches alerts, parses logs, and drafts mitigations continuously. AI proposes, humans approve anything destructive or irreversible.
Named incident response
A named incident-response contact and an SLA above Cloud VPS. You know who answers, and how fast, before anything goes wrong.
Independent testing
Quarterly external vulnerability scans and an annual third-party penetration test, with results shared on request.
What you add over Cloud VPS

Cloud VPS, plus everything an auditor asks for.

Compliant Dedicated starts from the managed, hardened Cloud VPS you already know, then adds the documentation, isolation, and assurance a regulated buyer requires.

Capability Cloud VPS Compliant Dedicated
Dedicated resources, fully managed & hardened
WAF, intrusion detection, malware scanning, encrypted backups
Single-tenant, no shared workloadsDedicated single tenant
Documented controls (ISO 27001 Annex A + SOC 2 TSC)Signed addendum
At-rest encryption with documented key custodyInfra-layerDocumented custody
Immutable audit logging1-year retention
Data residencyUS defaultUK / EU
Signed DPA + Standard Contractual ClausesOn requestIncluded
Named incident-response contactIncluded
Quarterly vulnerability scans + annual pen testIncluded
ISO 27001 certification roadmapTarget Q1 2027
Price$350–$750/moFrom $1,995/mo
Why machine-speed matters

The disclosure-to-exploitation window is now minutes.

Vulnerabilities are discovered and weaponized at machine speed. A host relying on a human on call responds in hours. Ours watches New Relic alerts, parses access logs, fingerprints attack patterns, and drafts fleet-wide mitigations continuously, so we respond at the speed the threat actually moves. The guardrail is deliberate: additive, reversible defenses can deploy automatically, but anything destructive or fleet-wide is reviewed by a person first. That boundary is what makes machine-speed defense safe enough to put in front of a private bank.

How an engagement runs

From discovery call to documented go-live

No surprises for your compliance team. Each step produces something they can review.

1
Discovery

We scope your requirements

A call to understand the buyers, the data, the regulatory frame (Cayman DPA, GDPR, sector rules), residency requirements, and what evidence your compliance team needs to see.

2
Build & document

We provision and harden

Single-tenant server in your chosen region, at-rest encryption and key custody configured, audit-log shipping enabled, controls documented, security addendum and DPA drafted for signature.

3
Go-live & evidence

We migrate, then keep the evidence flowing

Zero-downtime migration, named incident-response contact assigned, continuous evidence collection running. Surveillance and the ISO 27001 program proceed from there.

Let's scope your environment.

A discovery call, an honest read of what your compliance team needs, and a scoped build. If we are not the right fit for your requirements, we will tell you, and point you toward who is. Sourcing regulated or high-net-worth clients as an agency? We host the compliant layer and you keep the relationship.

– Ryan Davis, founder. Operating WordPress infrastructure since 2007.
Reply within 1 business hour No certificate we don't hold Free migration in and out, no lock-in