What's included
Most hosting companies describe managed support with a word — fully managed — and leave you to discover the edges when something breaks. We'd rather tell you where the edges are now.
So this page is the whole thing: what we look after, what stays with you, what sits outside the plan, and what happens when you ask us for something we don't cover. It's more detail than a features grid. That's deliberate — you're putting patient data on this, and you should know precisely who is responsible for what before you need the answer.
No limits on how often you ask
There's no cap on tickets, hours or requests. We don't meter support, and you'll never be told you've used up your allowance for the month.
What is defined is the kind of work included: we look after the server, the services running on it, and the security and compliance layer around it. We don't work inside your application.
How quickly we respond, and whether you reach an engineer directly or through a scheduled queue, does vary by plan. What counts as included work does not — the scope on this page is the same whether you're on our smallest plan or our largest.
That distinction is what makes the first promise possible. A hosting company that includes everything has to limit how often you ask. We'd rather be specific about the work and unlimited about the asking.
The short version
We run the server. You run what's on it.
We keep the operating system patched, the services healthy, the certificates valid, the firewall tight, the backups tested and the monitoring watching. You own your site, your code, your plugins, your data and the people who can log in to it.
A useful test if you're ever unsure: would this problem follow you to a different host? A broken plugin would. A failed system update wouldn't. The first is yours; the second is ours.
What we take care of
Your infrastructure
| Your own AWS account and VPC | Dedicated to you, never shared with another customer. Your environment is isolated from every other customer's by design, not by configuration. |
| The server itself | We build it, size it, resize it when you grow, and replace it if the underlying hardware fails. |
| Where it runs | You choose the AWS region. |
Keeping it patched and healthy
| Operating system and kernel | Security patches applied and reboots scheduled in a maintenance window we agree with you at setup. |
| The service stack | Web server, PHP, database server, Redis, Node, Docker engine — installed, patched and kept on supported versions. |
| Version upgrades | When something reaches end of life, we plan the move forward with you rather than leaving you on it. |
Security
| Encryption | Encrypted at rest with dedicated keys, and in transit with TLS. |
| TLS certificates | Issued, installed, renewed and monitored. An expiring certificate is our problem to catch, not your surprise on a Monday. |
| Firewall and security groups | Deny by default. Only what needs to be open is open. Where you ask us to open something beyond that baseline, we'll put the risk in writing before we do it. |
| Web application firewall and CDN | Included on every plan, with managed rule groups maintained for you. |
| Malware scanning and file integrity monitoring | Running continuously. |
| Vulnerability alerts | We tell you when a plugin, theme or extension you're running has a known vulnerability. |
| Access management | Named system accounts, SSH keys issued and revoked, access audited. Our own administrators use individual named accounts with multi-factor authentication. |
Getting you moved in
| Launch and setup | We build the instance and install the core services. That's the plan, not an extra. |
| 4 hours of migration and configuration, included | In your first month, starting once your server is live. On Starter, the four hours come with a 3-month commitment — your choice, and the plan stays month-to-month if you'd rather not. Every other plan includes them outright. |
| Beyond that | $175/hour, quoted before it starts. |
What the four hours cover. This list is complete, so you know exactly what you're getting:
- Moving your existing site, database and files onto the server
- The application configuration needed to complete that move — settings, environment variables, connection strings, cron and queue jobs
- DNS cutover
- Domain and TLS setup beyond what's issued automatically
- Choosing and tuning the firewall rules that protect your admin paths
- Setting up your staging environment, on plans that include one
- A handover walkthrough with your technical contact
Anything outside that list is quoted separately — it isn't drawn from your four hours, even if hours remain.
Scoped with you up front and delivered as scheduled working sessions rather than ad-hoc requests, so you get four hours of real progress rather than four hours spread thin. Planning happens in business hours; cutover can run out of hours. The four hours are for your move-in — they don't roll over.
Backups and recovery
| Automated backups | Snapshot storage at twice your plan's volume size. |
| Tested restores | We verify restores work rather than assuming they do. |
| Restores on request | Ask and we'll do it. |
Watching it
| 24/7 monitoring | Host and service health, around the clock. |
| Incident response | We detect, contain, restore service and tell you what happened. |
| Security monitoring | A SIEM with a 90-day live window and a six-year tamper-proof archive. |
| Audit logging | Full infrastructure audit trail and configuration recording. |
Compliance
| A signed BAA | Included on every plan. Not an upgrade, not an add-on. |
| The technical safeguards | Encryption, access control, audit controls, monitoring and backups — built in and documented. |
| Evidence when you're asked for it | We can show a reviewer how the hosting layer is controlled. Quarterly evidence packs are included from the Group plan. |
Depending on your plan
Higher plans add attention, not a different set of rules — the scope on this page is identical on every plan.
| Staging environment | Practice and above |
| Proactive log review | Clinic and above |
| Priority 24/7 SMS and email alerting | Clinic and above |
| Quarterly compliance evidence pack | Group and above |
| A named technical contact | Network |
What stays with you
Your application is yours. That's not us stepping back — it's that you're the only one who can safely make these calls.
Your code and your site. Application code, your CMS, plugins, themes, modules and extensions, and how they're configured.
Applying updates. We tell you when something you're running has a known vulnerability. You decide when to apply the update, because you're the one who can test that it didn't break your booking form. If you'd like someone to manage that for you, we can point you at people who do it well.
Your data. Content, records, and the database itself — its structure, its queries and what's in it.
Who can log in to your application. User accounts, roles and permissions inside your site.
Telling us when someone leaves. If a member of your team with server access moves on, we need to know so we can revoke it. We can't infer it, and it's the single most important thing on this list.
Your domain. Registration, renewal, and DNS records other than the ones for services we run.
Your own HIPAA obligations. Your risk analysis, your policies, your workforce training, and your decisions about who may see what. Hosting with us makes the infrastructure layer defensible and gives you evidence for it — it doesn't discharge the obligations that sit with you.
On Docker plans, your container images. On n8n plans, your workflows.
Where we stop — and what happens then
This is the part most scope documents get wrong, so here it is plainly.
We will always tell you whose problem it is. That's free, on every plan.
If your site is down, slow or throwing errors, we'll find out where the problem lives — no charge, no time limit, whatever plan you're on. That's true even when the answer turns out to be your application rather than our server.
And if it's yours, you don't get a shrug. You get the log line, the timestamp, the request ID and what we found, so whoever fixes it starts from evidence instead of from zero.
We think that's the part that actually matters. The fear isn't really the bill — it's being stuck between two suppliers who each say it's the other one's fault. That doesn't happen here.
What we don't do
We don't work inside your application. Specifically, we don't:
- Write, change, design or develop code, applications, plugins, themes, workflows, container images, templates or pages
- Optimize your queries, change your database structure, or edit your data
- Tune your application's performance — we'll size the server correctly and show you the evidence, but a slow theme is a development problem
- Support third-party software or services you've bought elsewhere
- Do SEO or marketing work
- Clean malware out of application code in place — we contain the incident and restore you from a clean backup, and remediating the code is a separate piece of work
What "we manage your server" doesn't mean
- It doesn't mean we update your plugins. We tell you which ones need it.
- It doesn't mean we debug your errors. We'll tell you it's an application error and hand you the evidence.
- It doesn't mean unlimited engineering. There's no limit on how often you ask. There is a firm limit on what kind of work is included — this page.
- It doesn't mean you're automatically HIPAA compliant. It means the hosting layer is, and you can prove it.
Things we're glad to do, quoted separately
Being outside the plan doesn't mean we won't do it. Most of it we will — it's just priced, because it's real engineering time rather than something every customer's monthly fee should cover.
- Malware remediation and forensic clean-up
- Performance investigation, with findings and recommendations
- Custom firewall rules tuned to your application
- Additional migrations beyond your move-in
- High-availability and multi-region architecture
- Private-access VPN for your staff, and site-to-site VPN to your own network
- Extra environments beyond your included staging
- Longer backup retention (monthly), scheduled exports and granular data recovery (hourly)
- Help completing a client's or payer's security questionnaire
- Custom monitoring for your application's own metrics
- Standby cover for a go-live or a scheduled event
- Root access, as part of an Enterprise engagement — a change of plan, not an hourly job
- Moving your DNS onto our management (your hosted zones themselves are included)
What it costs
We publish our rates rather than making you ask. Not everything outside your plan is hourly — some things are a monthly add-on, some are metered usage, and a couple are a change of plan rather than a job. We'll always tell you which.
Monthly add-ons
| Priority / Real-Time Alerting | Included from the Clinic plan up. On Starter, Solo and Practice it's $25/month per instance — 24/7 monitoring with real-time SMS and email alerts for downtime, server health and security events, delivered instantly to your team so problems are handled before they escalate. |
| Private-access VPN | $79/month, up to 10 users, plus setup |
| Site-to-site VPN, extra environments, longer backup retention | Quoted |
Metered usage, billed on your invoice: email sending through SES, and network transfer beyond your plan's allowance.
Hourly work
| Standard — business hours, scheduled | $175/hour |
| After-hours and emergency | $265/hour |
| On a proactive support plan | $125/hour |
| Pre-purchased block — 10 hours | $150/hour ($1,500) |
Minimum 30 minutes, then billed in 15-minute increments — the same minimum applies to your included onboarding hours.
Your first four hours are free. Every new plan includes 4 hours of migration and configuration work in the first month (see Getting you moved in). These rates apply after that.
Nothing chargeable starts without a quote you've agreed to. You'll get a straight answer and a number — not silence, and never a surprise invoice. If a job turns out to be larger than quoted, we come back to you before continuing rather than after.
And it's worth repeating what doesn't cost anything: working out whose problem it is, is always free. You only reach these rates once we've established the work is yours and you've asked us to do it anyway.
Straight answers
How available is it?
Your plan runs on a single dedicated server in a single AWS availability zone. That's a real machine with a real failure mode, and we'd rather say so than imply otherwise.
The commitment that applies to that architecture is AWS's instance-level uptime commitment of 99.5% per monthly billing cycle. You'll see 99.99% advertised elsewhere in the industry — that's AWS's region-level figure, and it applies to workloads spread across multiple availability zones. Ours isn't, so we don't quote it.
If you need higher availability than that, it's genuinely available — a multi-zone design is one of the engagements listed above, and we'll scope it honestly rather than sell you a number.
Do you hold SOC 2 or HITRUST?
No, and we won't imply otherwise. AWS holds those certifications at the infrastructure layer, and their audit reports are available to you through AWS Artifact.
For most healthcare diligence, what's actually needed is evidence that the controls exist and work — encryption, access control, audit logging, monitoring, backup testing, a signed BAA — and we can provide that. If SOC 2 is a hard contractual requirement from a payer or a state contract, tell us early and we'll say so rather than waste your time.
It's also worth knowing that there is no such thing as a HIPAA certificate. HHS doesn't certify anyone. Any hosting company telling you they're "HIPAA certified" is describing something that doesn't exist.
Is a VPN required for HIPAA?
No. The Security Rule's transmission security standard requires technical measures to protect health information moving across a network, and TLS — which every plan has — satisfies that. Encryption in transit is an addressable implementation specification, and the rule doesn't mention VPNs at all.
We offer one because it's genuinely useful for a different reason: it lets you restrict the sensitive parts of your site — the admin login, the database, your staging environment — to devices you control, while your public site stays public. That's a good security decision. It just isn't a legal requirement, and we won't sell it to you as one.
Where is your team based?
We're a global organization. Our engineers work from several countries, and every one of them is an employee of the company — not a contractor, and not an outsourced service desk.
That's the distinction that matters. Employees are workforce members under our direct control, which puts them inside the Business Associate Agreement we sign with you, rather than being a separate chain of subcontractors you'd need your own assurances about. Every employee completes the same security and privacy training, on the same schedule, wherever they're based — and we keep those records for your security review.
On location specifically: HIPAA doesn't restrict where protected health information may be accessed from. It restricts who may access it, and how. Some contracts do impose location terms, though — Medicare Advantage, some state Medicaid programs, and some payer agreements. If you're subject to one of those, tell us early and we'll work through it with you, including telling you plainly if we're not a fit.
Do you have a contract minimum?
No long-term contract on monthly plans. One-year and three-year prepayment terms are available if you'd prefer the discount.
What if I need root access?
Root access changes who's responsible for the server's security baseline, so it isn't available on standard plans — it would mean we could no longer stand behind the compliance work you're paying for. It's available through an Enterprise engagement, where the responsibilities get written down properly.
Why we publish this
A defined scope isn't a hedge. It's the difference between a support promise you can rely on and one that quietly means whatever we feel like on the day.
Because we've written down what we do, we can afford not to limit how often you ask. Because we've written down what we don't do, you'll never find out mid-incident that the thing you assumed was covered never was. And because diagnosis is always free, the boundary never becomes your problem to police.
If you're weighing us up and want to know whether something specific is included, just ask. You'll get a yes, or a price, or an honest referral — never a maybe.