Support ยท SSL, updates and monitoring included with hosting; audits quoted
Website security that starts with having less to attack
- Published
- Published
- Last reviewed
- Reviewed
The short answer
Most small-business website breaches come through outdated plugins, weak admin logins and shared hosting. Redenn removes those causes: static Next.js builds have no database or admin panel to attack on a brochure site, SSL and dependency updates come with hosting, and application tiers add authentication, row-level security and monitoring. Security audits of sites Redenn did not build are quoted.
What changes
- No plugin layer to exploit and no admin login on a static site
- Traffic encrypted with SSL that renews itself
- Dependencies updated monthly so known vulnerabilities are closed
- Application data protected at the database layer, not just in the interface
What is included
- Automatic SSL and secure headers on every tier
- Static builds with no server-side attack surface for brochure sites
- Monthly dependency updates on Business and above
- Authentication, row-level security and secrets management on Dynamic and above
- Error and access monitoring on Dynamic and above
- Registrar lock and two-factor on domains Redenn manages
How it works
- 01
Reduce the surface
Static where possible; a database only where genuinely needed.
- 02
Protect what remains
SSL, headers, authentication, least-privilege access and row-level security on application tiers.
- 03
Keep it current
Monthly updates close known vulnerabilities; monitoring watches for errors and abuse.
- 04
Respond
If something happens, the site is restored from backup and the cause is fixed and reported to you.
Who this is for
Every business, and especially those holding client information: law firms, clinics, accountants, immigration consultants, mortgage brokers. A breach there is a privacy incident with legal obligations, not just an outage.
If your current site runs on a stack of plugins with an admin login at a guessable address, an audit is the honest first step, and it may conclude that modernization is cheaper than hardening.
What is included by tier
| Control | Lite | Business | Dynamic | Pro Managed |
|---|---|---|---|---|
| SSL and secure headers | Yes | Yes | Yes | Yes |
| Static build, no admin panel | Yes | Yes, for static pages | Application has authenticated admin | Same, with staging |
| Monthly dependency updates | No | Yes | Yes | Yes |
| Authentication and roles | Not applicable | Not applicable | Yes | Yes |
| Row-level security on data | Not applicable | Not applicable | Yes | Yes |
| Error and access monitoring | No | No | Yes | Advanced, with alerts |
| Backups for recovery | Repository | Content | Content and database | Content, database, drills |
Application security
For sites with logins and data, these are the defaults on Dynamic and Pro Managed.
- Authentication through Supabase with password rules and optional two-factor
- Row-level security so the database refuses rows the user does not own
- Secrets kept in environment configuration, never in the repository
- Least-privilege access for staff roles and for Redenn's own access
- Logging of authentication events and errors, reviewed when alerts fire
What it costs
Security controls are part of hosting: Lite at CA$99 per year, Business at CA$199 per year, Dynamic at CA$49 per month and Pro Managed at CA$99 per month, each with the controls in the table. Audits of sites Redenn did not build are quoted after a review, and third-party penetration testing for regulated clients is arranged and billed by the testing firm.
Limitations and honest notes
No system is unbreachable. Redenn reduces the attack surface and keeps what remains current; it does not promise immunity.
Your own passwords, devices and staff practices are part of the perimeter. A strong site behind a reused password is not secure.
Redenn does not hold a security certification and does not claim one. Breach notification obligations under PIPEDA and provincial law are yours; we help you understand what happened and when.
Questions
Do I need a security plugin?
Not on a Redenn site. Security plugins exist to patch over problems that a static build and current dependencies do not have.
Is customer data encrypted?
In transit with SSL, and at rest on the managed database. Access is restricted by row-level security and roles.
What happens if the site is hacked?
The site is restored from backup, the cause is identified and fixed, and you receive a plain account of what happened and what data, if any, was affected.
Do you do penetration testing?
Not in-house. For clients who need it, we arrange an independent testing firm and fix what they find.
Related
Services
- Website HostingGlobal CDN, automatic SSL and monitoring from CA$99/year for static sites to CA$99/month for managed applications.
- Website BackupsCode in Git, content backed up on Business hosting and above, database backups on application tiers, restores tested.
- Website MaintenanceMonthly updates, backups, monitoring and fixes, included with Business hosting and above; larger work quoted.
- Customer PortalsA secure login area where clients see status, documents and invoices instead of emailing to ask.
- Web ApplicationsAccounts, data and workflows on Next.js and Supabase, scoped to a fixed price with a ship date in writing.
Guides
Industries
Support it. With website security.
Configure a website in minutes, or ask for a written quote. Quotes arrive within two business days.
