Host Luma preview URLs are served over HTTPS, and HTTPS extends to attached customer custom domains too.
Security
Security without pretending publishing is magic.
HostLuma.app is designed to hide server setup from customers while still making the important hosting controls visible: SSL, publishing status, logs and domain state.
Platform controls
What is included.
Customers do not need manual file uploads, shell access or server-path changes for the intended workflow.
Applications run under CloudLinux with resource limits (LVE) hand-tuned over 8+ months of operating real customer sites, so one busy application can't degrade another's performance.
Imunify360 runs continuous malware detection, cleaning and file isolation across the platform. WebShield blocks brute-force login attempts and blanket-bans XML-RPC abuse at the server level.
JetBackup 5 and native backup engines keep account data in three places: an offsite copy at Backblaze B2, a second copy on OVH remote storage, and local snapshots. No single point of failure holds the only copy.
Disclosure
Responsible disclosure.
If you believe you have found a security issue affecting HostLuma.app, contact support@hostluma.co.uk with enough detail to reproduce the issue. Do not access customer data, disrupt service or perform destructive testing.
A useful report includes the affected URL, expected behaviour, observed behaviour, reproduction steps, browser or tool details and any relevant timestamp. Please keep testing limited to your own account and sites.
This page avoids unsupported claims about uptime, certifications or audit status. Those should only be added when they are formally available.