Skip to content

Server security

We scan the server, clean it, and harden it.

Craftsman security work on the whole server: scan for malware, remove what we find, harden the box so the next attempt has nowhere to land.

A green dashboard is not the same as a clean server.

Automated security tools report in one color: green. The antivirus is green, the firewall is green, the login jail is green. The dashboard says everything is fine.

A server can wear that green for years while a compromise runs underneath it — because a signature scanner only catches what it already has a signature for, and the attack that matters is usually the one it doesn't.

Keystone is a security engagement for the whole server, not a plugin bolted inside one site. It scans the box the way a forensic responder would — every vhost, the operating system, the scheduler, the hosting-panel user layer — and returns a report that says what is actually there.

It runs on Beacon's engine, the same SSH transport and report discipline, pointed at the security of the machine itself.

Why it exists

The tools were all green. The box had been open for two years.

Keystone's playbook is built on a real incident. On the day it began, four separate automated defenses — antivirus, a web firewall, a login jail, a malware scanner — were all active and all reporting clean. The compromise underneath them was more than two years old.

That is the gap the product is built to close. Not another green light, but a human-grade read of the server that treats every signal as a question to investigate, and only reports a finding when the exact evidence can be pointed to.

Orange and silver padlock on orange door

Six layers, read across the whole box.

PHP execution paths

Every vhost read for obfuscated loaders, webshells, and tmp-file droppers — the executable code an attacker leaves behind to keep a way in.

Database integrity

Each WordPress database checked for injected spam, rogue admin accounts, and auto-provisioned users hiding in the options and cron rows.

The operating system

Rootkit indicators, sudoers anomalies, unexpected system users, rogue services, and SSH-key backdoors — the layer a per-site plugin can never see.

Versions and exposure

An inventory of out-of-date, abandoned, and known-vulnerable plugins, themes, and core across every site on the server.

Uploads and page builders

Dropper classes hiding in upload folders and builder assets: disguised PHP, double-extension files, polyglot images, malicious SVGs.

Persistence and cron

The scheduler and boot hooks read for the mechanisms that let an attacker survive a cleanup — cron jobs, reboot entries, credential leaks, key tampering.

The honesty line

A report that cannot quietly say pass.

The most dangerous line in a security report is a check that couldn't run, printed as if it did. A scanner that timed out, a layer with no access, a feed that wasn't wired — dressed up in green — is worse than no report at all.

Keystone's design center is a report that never lies about coverage. Every check resolves to one of three honest states: it ran with evidence, it couldn't run and says so plainly, or it errored. A layer that couldn't be verified is never described as clean.

Every finding is anchored to its evidence — a path, a line, a signature — and every report is honesty-audited before it ships.

A glass of water sitting on top of a table

When the scan comes back dirty.

That is the moment the discipline matters — what happens next is documented, reversible, and shown to the client at every step.

If something is found, malware removal is careful, provable, reversible.

  1. 01

    Back up before anything is touched

    First

    A dated forensic backup is taken and its path and size are stated to the client. Nothing on the server is altered until that backup exists and is verified.

  2. 02

    Quarantine, never delete

    Then

    Confirmed malware is moved to a timestamped quarantine with a hash written before the move — so every artifact stays recoverable and provable, and no evidence is destroyed.

  3. 03

    Name and close the way in

    Then

    The persistence mechanism is named explicitly and neutralized, and the entry point the attacker used is closed enough to stop the active bleeding.

  4. 04

    Prove the box is clean

    Then

    A fresh scan shows the flag cleared, and a full incident report reconstructs the timeline, inventories every artifact, and lists what was and was not compromised.

  5. 05

    Client-visible actions are recommended, never forced

    Always

    Rotating a password, forcing a re-login, removing a plugin in active use — these are recommended and require the client's explicit go before they run. Nothing user-facing changes on its own.

Three ways to run it.

The read-only diagnostic: six scan layers across the whole server, a forensic root-cause read where findings exist, and a ranked list of what to harden first.

It touches nothing and is safe on any box. It is the honest first look — and a baseline audit is a real deliverable even before any access is granted, because every check reads honestly rather than guessing.

Gold key on brown wooden table

Incident response, for a server that is actively compromised: backup first, quarantine not delete, the entry point closed, and proof the box is clean.

It is scoped and quoted per incident, and it holds the full safety discipline — nothing destructive without a verified backup, nothing user-facing without the client's authorization.

Brown and black brush on brown wooden table

A retainer: hardening kept installed and healthy, a scheduled re-scan on the same layers, and a periodic report that shows the verdict and any drift since last time.

It is periodic and tripwire-driven by design — a craftsman's rhythm, not a 24-hour security desk. Every tripwire alert is read by a person, not filed into an inbox nobody opens.

White padlock on white wooden door

The questions that come up first.

No. Keystone works at the server level over SSH — the operating system, the scheduler, the hosting-panel layer, and every site on the box.

A plugin can only see the site it lives in; a whole class of compromise lives outside that view, which is exactly where Keystone looks.

No. The Audit is read-only.

It reads the server and returns a report and makes zero changes. Only the Cleanup tier ever touches the box, and only after a verified backup, quarantining rather than deleting.

No, and it doesn't pretend to be. Watch is periodic and tripwire-driven: hardening tools do the watching between scheduled scans and alert on event.

There is a real gap window — up to roughly a day for some tripwires — between an event and detection. That is the honest tradeoff of craftsman work versus a real-time security desk, stated plainly rather than hidden.

It says so. A check that couldn't run is marked as unassessed, never as a pass.

A report that hides a blind spot behind a green light is the exact failure Keystone is built to prevent.

The whole discipline is built against that fear. A verified backup comes first, malware is quarantined rather than deleted with a hash recorded before the move, and any action a client would see is recommended and gated behind their explicit go.

The result is a cleanup that is reversible and provable, with an incident report a stakeholder can hand to a lawyer or an insurer.

Priced as an engagement, not a subscription tax.

Keystone is delivered as craftsman work — expert judgment and proprietary tooling together, run on Daylit's own infrastructure rather than sold as another per-site licence stacked on every property.

The Audit starts at around $350 as a one-time, read-only diagnostic for a single server. Cleanup is scoped and quoted per incident against what the audit finds. Watch is a monthly retainer that keeps the hardening installed and the server on a scheduled re-scan.

Every tier holds the same line: the audit changes nothing, a cleanup is backed up before it touches a file, and no report is ever allowed to call an unverified layer clean.