The full stack

Every layer, tuned by hand.

We've spent more time tuning database engines and web servers than we'd like to admit. Here's what that gets you.

PremiumNVMe Lightning-fast storage
Cloudflareedge DDoS shielded
0.00% Uptime SLA
24/7 Monitoring
Performance

Speed isn't a feature. It's the architecture.

Every layer pulls its weight — from kernel buffers to the page cache. Here's the actual stack, with the numbers we run it at.

Storage NVMe-only

Premium NVMe, no SATA layer

Enterprise NVMe on tuned bare metal. No networked SAN, no spinning disks behind an SSD cache.

HDD~120
SATA SSD~85K
NVMe850K
Random read · 4K · IOPS
Web server LiteSpeed

LiteSpeed engine, not Apache

LSCache for WordPress pre-tuned. Brotli compression. HTTP/3 + QUIC negotiated on every request.

HTTP/3 QUIC Brotli 0-RTT
Protocols · always-on
PHP runtime 8.3 + JIT

PHP 8.3, tuned for WordPress

OPcache and JIT tracing enabled. Generous per-request memory so heavy plugins don't OOM.

512 MB
Memory · Free
1 GB
Memory · Pro
2 GB
Memory · Studio
Database MariaDB

MariaDB, tuned for WP queries

Deep buffer pools, threaded query handling, IO tuned for NVMe latency. Redis sits on top as an object cache.

RedisHOT
InnoDBWARM
NVMeDISK
Caching Layered

Edge, page, and object — layered

Cloudflare's edge fronts the LiteSpeed page cache. Redis fronts the DB. The WP options table never touches disk on a warm cache.

HIT
Network 10 Gbit+

Tuned kernel network stack

BBR congestion control, tuned TCP buffers, jumbo frames where supported. Throughput holds under congestion instead of collapsing.

050100250+ ms
8.2 ms · cold-origin TTFB
Security

Defense in depth. Not as an upsell.

A request from the open internet passes through five layers before it can touch a database row. Each one is configured on day one — no add-ons, no premium SKUs.

01
Cloudflare edge

L3 / L4 / L7 DDoS scrubbing

Volumetric floods, SYN attacks, and HTTP request floods are dropped before they touch your origin. Origin IP is never exposed.

Always-on Origin hidden
02
WAF + Bot fight

OWASP ruleset + bot management

ModSecurity OWASP CRS plus Cloudflare's Bot Fight Mode. Injection, XSS, and credential-stuffing get the 403 before PHP runs.

OWASP CRS Bot Fight Mode
03
Origin firewall

Allowlist to Cloudflare's edge only

The origin firewall accepts inbound 443 from Cloudflare's published IP ranges and nothing else. SSH is key-only on a non-22 port.

CF allowlist Key-auth only
04
Application

Rate-limited login + audit log

Tunable rate-limit on /wp-login.php and /xmlrpc.php. Daily ImunifyAV malware scans. Every change is recorded in a per-site audit log.

Rate-limited Audit log
05
User auth

2FA on the hosting panel

TOTP 2FA is mandatory for the customer panel. Sessions auto-expire, SSH keys are scoped per environment, and IP allowlists are supported.

TOTP 2FA Session timeout
Reliability

Uptime measured. Credited automatically.

99.99% works out to a maximum of 4 m 23 s of downtime per month. Anything more and we credit your account before you have to ask.

Live status All systems operational

Real-time monitoring,
public and unfiltered.

Origin, database, edge and email each check in every 60 seconds. The dashboard at status.serverborn.com is the same one our on-call rotation watches — no curated marketing version.

60s
Heartbeat interval
3
External regions
<60s
Page on-call
View live status Powered by Uptime Kuma · public incident archive
SLA budget

What 99.99% means, in minutes

Monthly budget4 m 23 s
Used this month0 m 0 s
Remaining4 m 23 s
If we miss · automatic 10% credit on your next invoice
How it's defended

The mechanics behind the number

  • 30-second heartbeats from three external regions
  • Daily encrypted snapshots replicated to a second region · 30-day retention (60 on Studio)
  • One-click restore at file or full-site granularity
  • On-call paging within 60 seconds of a failed check
  • Public incident timeline · no after-the-fact spin
Developer experience

The tooling you'd actually wire up if you were running it yourself.

SSH + WP-CLI

Root over SSH on a non-22 port, key-auth only. WP-CLI, Composer, git, rsync, all pre-installed. Tail logs from your terminal.

One-click staging

Spin up an identical staging clone in 30 seconds. Push changes back to production from the panel, no SCP gymnastics.

Git deploy

Connect a GitHub repo, choose a branch, set the deploy path. Every push triggers a pull. Slack notifications optional.

Modern panel

A dark, fast, keyboard-friendly admin UI. File manager, terminal, log viewer, DNS, email — all in one place. No 2003-era cPanel.

Search-everywhere

Hit ⌘K in the panel and jump to any setting, site, or log in a couple of keystrokes.

Real logs, not summaries

Access, error, modsec, and PHP-FPM logs all tailable from the panel or over SSH. No stripped-down "log view" widget.

Forged for builders

Tooling that gets out of your way.
Hosting that stays out of the news.