Every server is an isolated KVM virtual machine with full root access. You control the firewall and software on your server; your account is protected with SSH keys and two-factor authentication.
What the platform provides, and what you configure yourself
Each server is its own KVM virtual machine on our Proxmox cluster, with its own kernel, memory and disk, separate from other customers.
No managed firewall sits in front of your server. Configure ufw, firewalld or nftables yourself; the web console still works if a rule locks you out of SSH.
The control panel and API use HTTPS and servers accept SSH key login. Add free Let's Encrypt certificates for your sites. Disks are not encrypted at rest.
Protect your VPS.org account with two-factor authentication, keep SSH keys in your account, and use API tokens for automation instead of sharing your password.
Reach your server from the browser through the control panel, even when SSH is down or a firewall rule blocks you. You can also reset the root password there.
Full control of your operating system and software, so you can apply the controls your own compliance program requires. VPS.org does not currently hold any third-party security or compliance certifications.
The platform handles some layers, and you handle the rest
No denial-of-service mitigation or traffic filtering is applied before traffic reaches your server. Use a proxy service such as Cloudflare for public sites that need it.
You configure the firewall inside your server. Nothing is blocked at the network level by default.
HTTPS protects the control panel and API, and SSH protects server access. Use Let's Encrypt for your own sites. Disks are not encrypted at rest.
fail2ban is not preinstalled. Use SSH keys, disable password login, and install fail2ban to stop brute-force attempts.
Free snapshots and optional paid daily or weekly backups. Both are stored on the same storage cluster as your server, so keep an off-site copy of important data.
Two-factor authentication and SSH keys protect access to your VPS.org account and new servers.
Common questions about security on VPS.org
No. VPS.org does not provide denial-of-service mitigation or traffic scrubbing. If you run a public site that may be attacked, put a proxy service such as Cloudflare in front of your server.
The control panel and API are served over HTTPS, and you reach your server over SSH. Disks and backups are not encrypted at rest, so encrypt sensitive data inside your server. You can add free Let's Encrypt certificates for your own sites.
No. There is no managed firewall between the internet and your server, so all ports your software opens are reachable. Configure a firewall inside the server with ufw, firewalld or nftables. If a rule locks you out of SSH, you can still log in through the web console in the control panel.
No. We do not run intrusion detection or malware scanning on customer servers. If you need them, install tools such as fail2ban, CrowdSec or a malware scanner inside your server.
VPS.org does not currently hold any third-party security or compliance certifications. You have full control of the operating system and software on your server, so you can apply the controls your own compliance program requires. If your workload needs a certified provider, contact our team before you deploy.
Backups and snapshots are compressed copies of your whole server, stored on the same storage cluster in the same New Jersey location as your server. They are not encrypted and not kept off-site, so keep your own off-site copy of important data. Snapshots are free; scheduled backups are a paid add-on.
No. Servers communicate over their public IPv4 or IPv6 addresses. To connect servers privately, set up an encrypted tunnel such as WireGuard between them.
Restore a snapshot or backup taken before the compromise, or reinstall the server from the control panel and restore your data. Change your passwords and SSH keys afterwards. Servers used for abuse may be suspended under our Acceptable Use Policy, and our support team can help you get your server back online.
fail2ban is not preinstalled. We recommend logging in with SSH keys, disabling password login, and installing fail2ban. If fail2ban is installed, the Access page of the control panel lists banned IP addresses and lets you unban them. Also enable two-factor authentication on your VPS.org account.
No. After your server is deployed, applying updates is your responsibility. Run your package manager (apt, dnf or apk) regularly, or enable automatic updates such as unattended-upgrades.
All VPS.org servers currently run in our New Jersey, USA location. Every server has IPv6 connectivity, with public IPv4 available on every plan, so it can serve users anywhere in the world.
You may run security tests against servers you own. Do not scan or test other customers' servers, other networks, or VPS.org infrastructure. Contact support first if your testing could affect anyone else.
Isolated virtual machines, SSH keys and two-factor authentication on every plan.
Get Started NowPlans starting at $2.50/month