Service · Server hardening

Server hardening for the VPS your app lives on.

A fresh VPS gets its first brute-force attempt within minutes of booting. Password SSH, no firewall, no backups and silent failed updates are how small servers die. We harden yours once, properly, then the platform watches it around the clock.

Get your server hardened → All services
01The hardening pass

The boring, critical work most projects skip.

Everything below is standard practice and almost nobody does all of it. We do the full pass on Ubuntu, Debian and the usual panels (Hetzner, DigitalOcean, OVH, aaPanel, Ploi, Forge), and document every change.

  • SSH: keys only, root login off, fail2ban with sane bans
  • Firewall: default-deny, only your service ports open
  • TLS: automatic issue and renew, HTTP redirected, HSTS on
  • Backups: nightly, off-server, with a tested restore, not just a cron line
  • Updates: unattended security patches with reboot windows
  • Users and permissions: app runs unprivileged, sudo audited
What the monitoring covers →
server · hardeninglocked
SSH keys only · root login off
ufw default-deny · 3 ports open
fail2ban · 214 IPs banned this week
TLS auto-renew · HSTS active
nightly backup · restore tested
 monitored 24/7 by Defen.so

Hardened and documented

Every change written down, nothing mysterious left behind.

02Why it matters

What actually happens to unhardened servers.

Brute-forced SSH

Bots try thousands of passwords per hour against port 22 from the moment your server gets an IP. Password auth eventually loses; keys plus fail2ban ends the game.

Cryptominers and botnets

A compromised box mines crypto or joins a botnet quietly. You find out from a CPU alert, an abuse report from your host, or a blacklisted IP.

Backups that never restore

Half of all backup setups fail on first restore: wrong paths, expired credentials, silently full disks. We test the restore, because an untested backup is a hope, not a backup.

Expired certificates

A TLS certificate that lapses on a weekend logs your users out and floods you with browser-warning screenshots. Automatic renewal plus expiry monitoring makes it a non-event.

Unpatched CVEs

Last year's OpenSSH or kernel vulnerability stays exploitable forever on a server nobody updates. Unattended security patches close the window without you thinking about it.

No one watching

Every safeguard degrades silently: disks fill, services crash, bans stop firing. Monitoring is the difference between an incident and an outage.

App-level security too? See the security audit and the managed WAF.

One server or a fleet, hardened this week.

Tell us the OS, the host and what runs on it. Fixed price per server, documented handover, monitored after.

Email info@defen.so → Start monitoring free

FAQ

Common questions

What does server hardening cost?

+
A fixed price per server, quoted after you tell us the OS, panel and what runs on it. Fleets get a per-server rate. The price includes the documented hardening pass, a tested backup restore, and wiring the server into monitoring.

Which systems do you support?

+
Ubuntu and Debian first-class, plus AlmaLinux and Rocky. Panels and tooling we work with daily: plain SSH, aaPanel, Ploi, Laravel Forge, Docker hosts, and VPSes on Hetzner, DigitalOcean, OVH, Vultr and AWS Lightsail.

Will hardening break my app?

+
No. Every change is applied with the app running and verified afterwards: firewall rules are tested against real traffic, SSH changes keep a second session open until keys are confirmed, and everything is documented so it can be reversed deliberately.

Do you need root access?

+
Yes, for the hardening pass itself, via a key you can revoke the moment we finish. Everything we run is listed in the handover document. We sign an NDA on request.

What monitoring runs afterwards?

+
Uptime checks with SSL and domain expiry warnings, alerting to email, Slack, Telegram or webhooks through the Defen.so platform, starting on the free tier. Optional deeper checks cover disk, services and scheduled jobs.

Is this a one-time service or a subscription?

+
The hardening pass is one-time and yours to keep: keys, docs and configs all belong to you. Ongoing monitoring runs on the platform at its normal plan pricing, and repeat passes (after big infrastructure changes) are simply quoted again.