Skip to main content
Technology

We build the whole thing ourselves

Our control panel, our API, our orchestrator, our bot protection. Owning every layer is more work, and it is the only reason some of what is on this site exists at all.

14 days free. No credit card. No commitment.

252 commands

One orchestrator

Same price

On renewal, every year

99.99%

Uptime, last 12 mo

Daily

Backups kept up to 30 days

E

190+

Tasks Ellie handles

Why we built it

Independence, and what it is for

There are good hosting platforms you can license, and most of the industry runs on them. We went the other way - not because those products are poor, but because the things we most wanted to build cut across every layer at once.

  • A feature can start at the web server and finish in the panel

    Bot protection is the clearest example. Scoring traffic by behaviour has to happen where the request lands, which meant writing it into the web server itself - and then the dashboard, the per-site controls and the API all had to exist for it. That is one change across four layers. It is only a single change if all four are yours.

  • Nothing waits for somebody else to ship

    When we find something worth fixing, the fix goes out on our schedule. There is no upstream ticket, no waiting for a release that bundles it with forty other changes, and no feature that has to be popular with a hundred thousand other hosts before it gets built.

  • No licence sits between you and a feature

    Panel and security suites are usually licensed per server, and the good tiers cost more. We do not carry that cost, which is part of why the security features here are in every plan instead of being the reason to upgrade.

  • The constraints are ours to weigh

    Every platform makes tradeoffs to work for everyone who uses it - which is the right call when that is your job. It just means the tradeoffs arrive with the product. Ours are decisions we made on purpose, and we can revisit them.

The short version

A platform you license is somebody else's roadmap. That is a perfectly good deal when their roadmap matches yours - and a constraint when it does not.

We wanted to score traffic by behaviour at the origin, put an assistant on top of every operation, and ship a fix the day we found it. None of those are things you can wait for.

The clearest example

Bot protection is the argument, made concrete

It is the feature that explains the whole approach, because there was no version of it we could have bought.

Scoring traffic on how it behaves - the pace, the order of paths, whether a client keeps a cookie or can answer a challenge - has to happen where the request actually lands. So it had to go into the web server itself, which is only an option if the web layer is yours to extend.

Then it needed somewhere to live: per-site controls, a dashboard, an API, whitelists, rate limits, and the same rules running at the edge as at the origin. Four layers, one feature. Every one of those had to be ours for the feature to be one project rather than four negotiations.

The result is on every plan, on by default, with no plugin inside your site and no service in front of it.

Things that exist because the layer was ours

  • Origin request scoringin the web server, not in front of it
  • Ellie190+ tools on our own API
  • The migration pluginwritten and published by us
  • One rule set, edge and originfrom a single codebase
  • Per-site security controlsbecause the panel is ours too

The stack

What is actually underneath

Standard, well-understood components at the bottom. The parts above them are ours.

What you touch

The control panel

Written from scratch rather than themed on top of something else. Real-time dashboards, a web terminal, a file manager, and every feature on this site reachable from one place - because the panel and the API were designed together rather than one wrapping the other.

E

Ellie

The assistant is not a chat widget bolted to a knowledge base. She calls 190+ real tools against the same API the buttons use, which is only possible because we own the API and could give every action a machine-callable shape.

What runs it

The backend API

Queue-driven, audit-logged, and the single place any change to your account goes through - whether it came from a button, from Ellie, or from an automation. One path means one set of validations and one record of what happened.

The orchestrator

A compiled binary on every server with 252 registered commands across twenty modules - users, web server, PHP, containers, MySQL, FTP, DNS, caching, certificates, firewall. The panel never runs shell strings at a server; it calls this, and this does the work the same way every time.

Containers and the web layer

Podman for per-account isolation on Rocky Linux, with an OpenResty-based web layer we can extend directly - which is where the request scoring lives. Provisioning is Ansible, so a new server is a run rather than a checklist.

What we did with it

Behavioural bot protection at the origin

Scored in real time on how traffic behaves, with challenges and fleet-wide bans, running on the server rather than bought as a service in front of it. This is the thing that could not have been an add-on, and it is on every plan.

Migration tooling of our own

A WordPress plugin we wrote and publish, plus an SSH path that finds your installation for you. Both pull rather than push, both were built around what other hosts actually allow, and neither is a generic import script.

An edge we control

The same protection logic runs at the edge as at the origin, from one codebase, so a rule does not mean one thing in front of your site and something else on it.

Rocky LinuxPodmanOpenRestyMySQLAnsibleNode.jsGoReact

The foundations are boring on purpose. Inventing a filesystem is not independence, it is homework.

The other side

What it costs to do it this way

Owning everything is not free, and a page arguing for it should say what you give up.

  • You will not find cPanel here

    If your muscle memory is cPanel or Plesk, ours is a different panel and there is a short adjustment. Plenty of people arrive expecting to miss it; most do not, but it is a real first week either way.

  • The ecosystem is smaller

    A widely-used panel has years of forum answers, third-party integrations and scripts written against it. We have documentation, an assistant that knows the platform, and people who answer tickets - which is different, and better in some situations and not others.

  • Everything is on us

    There is nobody upstream to escalate to. When something is broken it is ours to fix, and when something is missing it is ours to build. That is the deal we wanted, and it is worth knowing that it is the deal.

This is a preference, not a verdict

Plenty of excellent hosting runs on licensed platforms, built by people who know exactly what they are doing. We are not claiming they are wrong - we are explaining why we chose the harder path, and what it bought.

Why it is reliable

One path for every change

A custom stack is only an advantage if it behaves the same way every time. That is an architecture decision, not a promise.

  • Nothing improvises

    The panel never runs a command at a server itself. It calls the orchestrator, which has one implementation of each operation - so the same thing happens whether you clicked it, Ellie proposed it, or a scheduled job triggered it.

  • Validated before it runs

    Inputs are checked centrally rather than per route, and an operation that cannot succeed is refused with a reason rather than half-applied and left to be discovered later.

  • Recorded after it does

    Every change is audit-logged with what it was before and after. That covers automation and the assistant as well as people, so "what happened here" always has an answer.

Pricing

Simple, transparent pricing

Every plan includes managed WordPress, SSH access, daily backups, and enterprise-grade security. Start with a 14-day free trial.

Startup

Great for growing businesses

$7.99/mo

$94.99 billed annually

  • 1 website
  • 10 GB storage
  • ~10,000 visits/month
  • 5 MySQL databases
  • 250,000 inodes
  • 5 FTP users

What's included:

SSL & Domain

  • Free SSL certificate
  • Free starter domain

Apps & CMS

  • 1-click WordPress
  • Managed WordPress
  • WordPress staging
Most popular

Advanced

For professional websites

$14.99/mo

$179.99 billed annually

  • 5 websites
  • 20 GB storage
  • ~110,000 visits/month
  • 10 MySQL databases
  • 500,000 inodes
  • 10 FTP users

Everything in Startup, plus:

Backups

  • 14 days of backup history

Performance

  • Memcached object cache
  • Redis object cache

Monitoring

  • 5 minutes between checks

Pro

Maximum performance and features

$22.99/mo

$274.99 billed annually

  • 10 websites
  • 40 GB storage
  • ~200,000 visits/month
  • 20 MySQL databases
  • 750,000 inodes
  • 20 FTP users

Everything in Advanced, plus:

Deployment

  • 2 SSR applications

Backups

  • 30 days of backup history

Monitoring

  • 1 minute between checks

Try it

The best argument is using it

Everything on this page is in every plan - the bot protection, the assistant, the panel, the isolation. Fourteen days free, no credit card.

Questions

Frequently asked questions

Why not build on cPanel or CloudLinux like everyone else?
They are solid products and there is nothing wrong with the choice - most of the industry makes it, and for good reasons. It just was not the right one for what we wanted to do. The features we care most about, starting with bot protection, needed changes at the web server, in the panel, in the API and in the provisioning at the same time. That is straightforward when every layer is yours and awkward when some of them belong to someone else and move on their own schedule.
Is a custom stack riskier than a standard one?
It is a real trade and worth naming. You give up a large ecosystem and the comfort of the familiar, and you take on responsibility for everything. What you get back is that nothing has to be worked around: no waiting on an upstream release, no feature we cannot add because it does not fit somebody else's model, and no compromise inherited from a product built to satisfy a hundred thousand different hosts.
Does building it yourselves make it cheaper?
It removes a cost. Panel and security licences are usually charged per server, and they add up quickly across a fleet. We do not pay them, which is a large part of why bot protection, backups, the WAF and the assistant are in every plan rather than being the reason to move up one.
What is the orchestrator, in plain terms?
A single compiled program installed on every server, with 252 commands covering users, the web server, PHP, containers, MySQL, FTP, DNS, caching, certificates and the firewall. The control panel never reaches into a server directly - it asks the orchestrator, and the orchestrator does the same thing the same way every time. That is what makes an operation you trigger from the panel identical to one Ellie triggers, or one an automation does at three in the morning.
Do you run SELinux?
Yes, enabled and enforcing on the hosts - which is worth mentioning because some popular panels require it to be switched off to function. It is one layer among several rather than the thing everything rests on; the isolation guarantees come from the container configuration, which is set out on the security page.
How does Ellie avoid making things up?
We separated understanding from doing. She interprets the request and picks one of 190+ tools; the panel executes it through the same API its own buttons use, after you confirm. The model never touches a server, never writes a configuration file and never runs a command - it chooses, and a deterministic system acts.
How long has this been running?
In production since 2022, on infrastructure-as-code so every server is provisioned the same way, with commands validated before they execute and a full audit trail of every change. It is custom, not improvised.